CVE-2021-26102

A relative path traversal vulnerability (CWE-23) in FortiWAN version 4.5.7 and below, 4.4 all versions may allow a remote non-authenticated attacker to delete files on the system by sending a crafted POST request. In particular, deleting specific configuration files will reset the Admin password to its default value.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:fortinet:fortiwan:*:*:*:*:*:*:*:*

History

21 Jan 2025, 20:29

Type Values Removed Values Added
References () https://fortiguard.fortinet.com/psirt/FG-IR-21-048 - () https://fortiguard.fortinet.com/psirt/FG-IR-21-048 - Vendor Advisory
First Time Fortinet fortiwan
Fortinet
Summary
  • (es) Una vulnerabilidad de path traversal relativo (CWE-23) en FortiWAN versión 4.5.7 y anteriores, 4.4 y todas las versiones puede permitir que un atacante remoto no autenticado elimine archivos del sistema mediante el envío de una solicitud POST manipulada. En particular, la eliminación de archivos de configuración específicos restablecerá la contraseña de administrador a su valor predeterminado.
CWE CWE-22
CPE cpe:2.3:a:fortinet:fortiwan:*:*:*:*:*:*:*:*

19 Dec 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-19 14:15

Updated : 2025-01-21 20:29


NVD link : CVE-2021-26102

Mitre link : CVE-2021-26102

CVE.ORG link : CVE-2021-26102


JSON object : View

Products Affected

fortinet

  • fortiwan
CWE
CWE-305

Authentication Bypass by Primary Weakness

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')