VYPR
High severity7.1NVD Advisory· Published Sep 13, 2023· Updated Jun 17, 2026

CVE-2023-36634

CVE-2023-36634

Description

An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpreter of FortiAP-U 7.0.0, 6.2.0 through 6.2.5, 6.0 all versions, 5.4 all versions may allow an authenticated attacker to list and delete arbitrary files and directory via specially crafted command arguments.

Affected products

4
  • cpe:2.3:a:fortinet:fortiap-u:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:fortinet:fortiap-u:*:*:*:*:*:*:*:*range: >=5.4.0,<=5.4.6
    • cpe:2.3:a:fortinet:fortiap-u:7.0.0:*:*:*:*:*:*:*
    • (no CPE)range: 7.0.0, 6.2.0 through 6.2.5, 6.0 all versions, 5.4 all versions
  • Range: 7.0.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.