Critical severity9.8NVD Advisory· Published Oct 18, 2022· Updated Jun 17, 2026
CVE-2022-33872
CVE-2022-33872
Description
An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in Telnet login components of FortiTester 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated remote attacker to execute arbitrary command in the underlying shell.
Affected products
3cpe:2.3:a:fortinet:fortitester:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:fortinet:fortitester:*:*:*:*:*:*:*:*range: >=2.3.0,<3.9.2
- (no CPE)range: 2.3.0-3.9.1, 4.0.0-4.2.0, 7.0.0-7.1.0
Patches
Vulnerability mechanics
References
1- fortiguard.com/psirt/FG-IR-22-237nvdVendor Advisory
News mentions
0No linked articles in our index yet.