VYPR
High severity7.2NVD Advisory· Published Oct 31, 2019· Updated Jun 17, 2026

CVE-2019-15710

CVE-2019-15710

Description

An OS command injection vulnerability in FortiExtender 4.1.0 to 4.1.1, 4.0.0 and below under CLI admin console may allow unauthorized administrators to run arbitrary system level commands via specially crafted "execute date" commands.

Affected products

3
  • cpe:2.3:o:fortiguard:fortiextender_firmware:*:*:*:*:*:*:*:*
    Range: <=4.1.1
  • Fortinet/FortiExtenderllm-fuzzy2 versions
    4.1.0 to 4.1.1, 4.0.0 and below+ 1 more
    • (no CPE)range: 4.1.0 to 4.1.1, 4.0.0 and below
    • (no CPE)range: 4.1.0 to 4.1.1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.