Fortinet FortiADC OS Command Injection Vulnerability Allowing Unauthorized Code Execution

Vulnerability

A vulnerability allowing OS command injection has been identified in Fortinet FortiADC versions 7.6.0 to 7.6.1, 7.4.0 to 7.4.6, 7.2.0 to 7.2.7, 7.1.0 to 7.1.4, as well as all versions of 7.0, 6.2, and 6.1. This vulnerability arises from improper neutralization of special elements used in OS commands, potentially allowing an authenticated attacker to execute unauthorized code by sending crafted HTTP requests.

Impact

Exploitation of this vulnerability could lead to unauthorized code execution on the affected system.

Added: Jun 10, 2025, 6:27 PM
Updated: Jun 10, 2025, 6:27 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
7.5
exploitability
5.4
remediation
0.0
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.