High severity7.2NVD Advisory· Published Oct 31, 2019· Updated Jun 17, 2026
CVE-2019-15710
CVE-2019-15710
Description
An OS command injection vulnerability in FortiExtender 4.1.0 to 4.1.1, 4.0.0 and below under CLI admin console may allow unauthorized administrators to run arbitrary system level commands via specially crafted "execute date" commands.
Affected products
3- cpe:2.3:o:fortiguard:fortiextender_firmware:*:*:*:*:*:*:*:*Range: <=4.1.1
4.1.0 to 4.1.1, 4.0.0 and below+ 1 more
- (no CPE)range: 4.1.0 to 4.1.1, 4.0.0 and below
- (no CPE)range: 4.1.0 to 4.1.1
Patches
Vulnerability mechanics
References
1- fortiguard.com/psirt/FG-IR-19-273nvdVendor Advisory
News mentions
0No linked articles in our index yet.