Executive brief
FortiAP is a wireless access point used to provide Wi-Fi connectivity in corporate environments. A security flaw in its command-line interface allows an authorized user with high-level access to run restricted system commands. This could lead to a full takeover of the device, potentially allowing an attacker to disrupt wireless services or gain a deeper foothold in the network.
Technical details
An OS command injection vulnerability (CWE-78) exists in the CLI component of Fortinet FortiAP and FortiAP-W2. The flaw is caused by improper neutralization of special elements within CLI commands. An authenticated attacker with high privileges can exploit this by submitting a specifically crafted command to execute arbitrary code at the operating system level. The attack vector is classified as local (AV:L) because it requires access to the device's management interface. Patches are available in FortiAP versions 7.6.3, 7.4.6, and FortiAP-W2 version 7.4.5.
Affected products
- Fortinet FortiAP 7.6.0 through 7.6.2, 7.4.0 through 7.4.5, 7.2 all versions, 7.0 all versions, 6.4 all versions
- Fortinet FortiAP-W2 7.4.0 through 7.4.4, 7.2 all versions, 7.0 all versions
Timeline
- 2026-05-12: disclosed: Initial publication by Fortinet
- 2026-05-12: advisory: NVD entry created