Executive brief
Fortinet FortiAP is a wireless access point used to provide Wi-Fi connectivity in enterprise environments. A vulnerability in its command-line interface allows an administrator with high-level privileges to bypass security restrictions and execute unauthorized system commands. This could lead to full control over the device, potentially impacting the security of the wireless network.
Technical details
An OS command injection vulnerability (CWE-78) exists in the Command Line Interface (CLI) of several FortiAP product lines. The flaw stems from improper neutralization of special elements within CLI requests. An attacker must already possess high-level administrative privileges to exploit this vulnerability. By submitting specially crafted CLI commands, the attacker can execute arbitrary code or system-level commands on the underlying operating system. Fortinet has released firmware updates (e.g., 7.6.3, 7.4.6, 7.0.6) to address these issues across the affected product families.
Affected products
- Fortinet FortiAP 7.6.0 through 7.6.2, 7.4.0 through 7.4.5, 7.2 all versions, 7.0 all versions, 6.4 all versions
- Fortinet FortiAP-U 7.0.0 through 7.0.5, 6.2 all versions
- Fortinet FortiAP-W2 7.4.0 through 7.4.4, 7.2 all versions, 7.0 all versions
Timeline
- 2026-05-12: advisory: Initial publication by Fortinet