High severity7.2NVD Advisory· Published Apr 6, 2022· Updated Jun 17, 2026
CVE-2021-24009
CVE-2021-24009
Description
Multiple improper neutralization of special elements used in an OS command vulnerabilities (CWE-78) in the Web GUI of FortiWAN before 4.5.9 may allow an authenticated attacker to execute arbitrary commands on the underlying system's shell via specifically crafted HTTP requests.
Affected products
3Patches
Vulnerability mechanics
References
1- fortiguard.com/psirt/FG-IR-21-060nvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.