Skip to main content

Vendor/product archive

fortinet / fortiwlc CVEs

Beta · best-effort

14 CVEs tagged to fortinet / fortiwlc4 Critical, 4 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2021-32584

Published Mar 17, 2025

An improper access control (CWE-284) vulnerability in FortiWLC version 8.6.0, version 8.5.3 and below, version 8.4.8 and below, version 8.3.3 and below, version 8.2.7 to 8.2.4, ve…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-26087

Published Mar 17, 2025

An improper neutralization of input during web page generation in FortiWLC version 8.6.0, version 8.5.3 and below, version 8.4.8 and below, version 8.3.3 web interface may allow b…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22126

Published Mar 17, 2025

A use of hard-coded password vulnerability in FortiWLC version 8.5.2 and below, version 8.4.8 and below, version 8.3.3 to 8.3.2, version 8.2.7 to 8.2.6 may allow a local, authenti…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-23439

Published Jan 22, 2025

A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` heade…

CVSS 4.7 · Medium

CVE-2021-26093

Published Dec 19, 2024

An access of uninitialized pointer (CWE-824) vulnerability in FortiWLC versions 8.6.0, 8.5.3 and earlier may allow a local and authenticated attacker to crash the access point bei…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2021-42758

Published Dec 8, 2021

An improper access control vulnerability [CWE-284] in FortiWLC 8.6.1 and below may allow an authenticated and remote attacker with low privileges to execute any command as an admi…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-9288

Published Jun 22, 2020

An improper neutralization of input vulnerability in FortiWLC 8.5.1 allows a remote authenticated attacker to perform a stored cross site scripting attack (XSS) via the ESS profil…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-17540

Published May 8, 2018

The presence of a hardcoded account in Fortinet FortiWLC 8.3.3 allows attackers to gain unauthorized read/write access via a remote shell.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-17539

Published May 8, 2018

The presence of a hardcoded account in Fortinet FortiWLC 7.0.11 and earlier allows attackers to gain unauthorized read/write access via a remote shell.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-7341

Published Oct 26, 2017

An OS Command Injection vulnerability in Fortinet FortiWLC 6.1-2 through 6.1-5, 7.0-7 through 7.0-10, 8.0 through 8.2, and 8.3.0 through 8.3.2 file management AP script download w…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2017-7335

Published Oct 26, 2017

A Cross-Site Scripting (XSS) vulnerability in Fortinet FortiWLC 6.1-x (6.1-2, 6.1-4 and 6.1-5); 7.0-x (7.0-7, 7.0-8, 7.0-9, 7.0-10); and 8.x (8.0, 8.1, 8.2 and 8.3.0-8.3.2) allows…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-8491

Published Feb 1, 2017

The presence of a hardcoded account named 'core' in Fortinet FortiWLC allows attackers to gain unauthorized read/write access via a remote shell.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-7561

Published Oct 5, 2016

Fortinet FortiWLC 6.1-2-29 and earlier, 7.0-9-1, 7.0-10-0, 8.0-5-0, 8.1-2-0, and 8.2-4-0 allow administrators to obtain sensitive user credentials by reading the pam.log file.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2016-7560

Published Oct 5, 2016

The rsyncd server in Fortinet FortiWLC 6.1-2-29 and earlier, 7.0-9-1, 7.0-10-0, 8.0-5-0, 8.1-2-0, and 8.2-4-0 has a hardcoded rsync account, which allows remote attackers to read…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-14 of 14 CVEsPage 1 of 1