CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
Wavlink AC3000 OpenVPN Command Execution Vulnerability
A vulnerability allowing arbitrary command execution exists in the Wavlink AC3000 router, specifically in the OpenVPN configuration handling within the openvpn.cgi file, version M33A8.V5030.210505. This vulnerability arises from improper authentication checks on .cgi binaries, allowing authenticated users to send specially crafted HTTP requests that are executed with system privileges.
Wavlink AC3000 Buffer Overflow Vulnerability in TR069 Functionality
A buffer overflow vulnerability has been identified in the Wavlink AC3000 router, specifically in the adm.cgi file's set_TR069() function, within the firmware version M33A8.V5030.210505. This vulnerability allows for a stack-based buffer overflow, which can be triggered by an authenticated user sending a specially crafted HTTP request. The lack of proper input validation in the TR069-related parameters enables the exploitation of this vulnerability, potentially leading to arbitrary code execution.
Wavlink AC3000 OS Command Injection Vulnerability in adm.cgi set_ledonoff() Function
A command injection vulnerability has been identified in the Wavlink AC3000 router, specifically in the adm.cgi file within the set_ledonoff() function. This vulnerability allows authenticated attackers to execute arbitrary commands on the device. The issue arises from the way the router's web interface handles HTTP requests, particularly those directed to .cgi scripts.
Wavlink AC3000 Buffer Overflow Vulnerability in adm.cgi rep_as_bridge() Function
A buffer overflow vulnerability has been identified in the Wavlink AC3000 router, specifically in the adm.cgi file within the rep_as_bridge() function. This vulnerability, present in version M33A8.V5030.210505, allows for a stack-based buffer overflow when a specially crafted HTTP request is sent. The issue can be triggered by an authenticated user.
Wavlink AC3000 Wireless Router Stack-Based Buffer Overflow Vulnerability in CGI Interface Allowing Arbitrary Command Execution
A stack-based buffer overflow vulnerability has been identified in the Wavlink AC3000 router, specifically in the 'wireless.cgi' file within the 'set_wifi_basic()' function. This vulnerability arises because the function does not properly validate the length of certain POST parameters, allowing for arbitrary data to be written to the stack. An authenticated attacker can exploit this vulnerability by sending a specially crafted HTTP request, potentially leading to arbitrary command execution on the device.
Wavlink AC3000 Command Execution Vulnerability in qos.cgi
A command execution vulnerability has been identified in the Wavlink AC3000 router, specifically in the qos.cgi file within the qos_sta() function. This vulnerability allows for arbitrary command execution via a specially crafted HTTP request. The issue arises because the router's lighttpd server configuration permits unauthenticated access to .cgi binaries in the web root, leaving it up to the binaries to verify user authentication. Once authenticated, an attacker can exploit the vulnerability by injecting commands that are executed by the router's cron service.
Wavlink AC3000 Buffer Overflow Vulnerability in login.cgi Goto_chidx() Function
A buffer overflow vulnerability has been identified in the Wavlink AC3000 router, specifically in the login.cgi file's Goto_chidx() function, within the firmware version M33A8.V5030.210505. This vulnerability allows for a stack-based buffer overflow, triggered by a specially crafted HTTP request. The issue arises because the login.cgi binary does not require authentication, leaving the router open to exploitation by anyone with network access.
Wavlink AC3000 Buffer Overflow Vulnerability in usbip.cgi set_info() Function
A buffer overflow vulnerability has been identified in the Wavlink AC3000 router, specifically in the usbip.cgi set_info() function, version M33A8.V5030.210505. This vulnerability allows for a stack-based buffer overflow, which can be triggered by an authenticated user sending a specially crafted HTTP request. The issue arises because the set_info() function does not properly validate the length of input data before copying it to the stack, creating an opportunity for an attacker to overwrite the return address and potentially execute arbitrary code.
Wavlink AC3000 Stack-Based Buffer Overflow Vulnerability in touchlist_sync.cgi Allowing Arbitrary Code Execution
A stack-based buffer overflow vulnerability has been identified in the Wavlink AC3000 router, specifically in the touchlist_sync.cgi file within the touchlistsync() function. This vulnerability arises because the CGI binary does not properly validate user authentication, allowing an attacker to send a specially crafted HTTP request that can be exploited to execute arbitrary code. The issue is present in the Wavlink AC3000 model M33A8.V5030.210505.
Wavlink AC3000 Command Injection Vulnerability in wireless.cgi AddMac() Function
A command injection vulnerability has been identified in the Wavlink AC3000 router, specifically in the wireless.cgi AddMac() function of version M33A8.V5030.210505. This vulnerability allows authenticated attackers to execute arbitrary commands on the router by sending specially crafted HTTP requests. The issue arises because the AddMac() function does not properly validate or sanitize input before executing it as a command, leading to potential unauthorized command execution.
Wavlink AC3000 Command Injection Vulnerability in touchlist_sync.cgi
A command injection vulnerability has been identified in the Wavlink AC3000 router, specifically in the touchlist_sync.cgi file within the touchlistsync() function. This vulnerability allows for arbitrary code execution via a crafted HTTP request. The issue arises because the CGI binary does not properly validate user authentication, leaving it open to exploitation by anyone with network access to the device.
Wavlink AC3000 Command Execution Vulnerability in TR069 Functionality
A command execution vulnerability has been identified in the Wavlink AC3000 router, specifically in the adm.cgi set_TR069() function of version M33A8.V5030.210505. This vulnerability allows authenticated attackers to execute arbitrary commands by sending specially crafted HTTP requests. The issue arises because the TR069_local_port parameter can be manipulated to inject commands, which are then executed by the router's operating system.
Howyar UEFI Application Reloader Secure Boot Bypass Vulnerability
A vulnerability in the Howyar UEFI Application 'Reloader' allows for the execution of unsigned software from a hard-coded path, bypassing UEFI Secure Boot. This issue affects both 32-bit and 64-bit versions of the application, which is distributed as part of several real-time system recovery software suites. The vulnerability arises because the Reloader application does not use standard UEFI functions to load applications securely, enabling the execution of arbitrary code during the boot process with high privileges.
Fortinet FortiMail and FortiRecorder OS Command Injection Vulnerability
A command injection vulnerability has been identified in Fortinet FortiMail versions 7.2.0 to 7.2.4, 7.0.0 to 7.0.6, and 6.4.0 to 6.4.7, as well as FortiRecorder versions 7.0.0 and 6.4.0 to 6.4.4. This vulnerability allows attackers to execute unauthorized code or commands via the command line interface (CLI) by improperly neutralizing special elements used in operating system commands.
Fortinet FortiWeb SQL Injection Vulnerability Allowing Information Disclosure
A SQL injection vulnerability has been identified in Fortinet FortiWeb versions 6.3.17 through 7.6.1. This vulnerability arises from improper neutralization of special elements used in SQL commands, allowing attackers to execute crafted SQL queries that could lead to unauthorized information disclosure.
Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability in WebSocket Module Granting Super-Admin Privileges
A vulnerability allowing authentication bypass via an alternate path or channel has been identified in Fortinet FortiOS versions 7.0.0 to 7.0.16, as well as FortiProxy versions 7.0.0 to 7.0.19 and 7.2.0 to 7.2.12. This vulnerability allows remote attackers to gain super-admin privileges by sending crafted requests to the Node.js WebSocket module.
Fortinet FortiOS and FortiProxy HTTP Response Splitting Vulnerability Allowing Code Execution
A vulnerability allowing HTTP response splitting has been identified in Fortinet FortiOS versions 7.2.0 to 7.6.0 and FortiProxy versions 7.2.0 to 7.4.5. This vulnerability arises from improper handling of carriage return and line feed (CRLF) sequences in HTTP headers, which can be exploited by attackers to execute unauthorized code or commands by crafting specific HTTP headers.
Fortinet FortiSIEM SQL Injection Vulnerability in Multiple Versions
A SQL injection vulnerability has been identified in Fortinet FortiSIEM versions 7.1.7 and below, 7.1.0, 7.0.3 and below, 6.7.9 and below, 6.7.8, 6.6.5 and below, 6.5.3 and below, and 6.4.4 and below. This vulnerability allows authenticated attackers to extract database information by sending crafted requests through the Update/Create Case feature.
Fortinet FortiPortal Basic Cross-Site Scripting Vulnerability
A cross-site scripting vulnerability has been identified in Fortinet FortiPortal versions 6.0.0 to 6.0.14. This issue arises from improper handling of script-related HTML tags, allowing attackers to execute unauthorized code or commands through HTML injection.
Fortinet FortiOS Denial-of-Service Vulnerability via Out-of-Bounds Write
A denial-of-service vulnerability has been identified in Fortinet FortiOS versions 7.6.0, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, and 6.4.0 through 6.4.15. The issue arises from an out-of-bounds write that allows attackers to disrupt services by sending specially crafted packets.
Fortinet FortiManager OS Command Injection Vulnerability Allowing Remote Code Execution
An OS command injection vulnerability has been identified in Fortinet FortiManager. This issue affects versions 7.6.0 through 7.6.1, 7.4.5 through 7.4.0, and 7.2.1 through 7.2.8, as well as FortiManager Cloud versions 7.6.0 through 7.6.1, 7.4.0 through 7.4.4, and 7.2.2 through 7.2.7. The vulnerability arises from improper neutralization of special elements in OS commands, which may allow an authenticated remote attacker to execute unauthorized code by sending crafted FGFM requests.
Fortinet FortiClient Windows Hard-Coded Cryptographic Key Vulnerability Allowing Decryption of Interprocess Communication
A vulnerability exists in Fortinet FortiClient for Windows in versions 7.4.0, 7.2.x (all versions), 7.0.x (all versions), and 6.4.x (all versions). The issue arises from the use of a hard-coded cryptographic key, which may enable a low-privileged user to decrypt interprocess communication by monitoring named pipes.
Fortinet FortiSOAR Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in Fortinet FortiSOAR versions 7.3.0 to 7.3.3 and 7.2.1 to 7.2.2. This vulnerability arises from improper input neutralization during web page generation, potentially allowing an authenticated attacker to inject malicious scripts through the creation of harmful playbooks.
Fortinet FortiSOAR IMAP Connector OS Command Injection Vulnerability
A vulnerability allowing OS command injection has been identified in the FortiSOAR IMAP connector, specifically in versions through 3.5.7. This vulnerability arises from improper neutralization of special elements used in OS commands, potentially allowing an authenticated attacker to execute unauthorized code or commands by crafting a specific playbook.
Fortinet FortiOS, FortiProxy, FortiManager, and FortiAnalyzer Cloud Weak Authentication Vulnerability Allowing Unauthorized Code Execution
A vulnerability exists in Fortinet FortiOS (versions 7.4.0 to 7.4.4, 7.2.0 to 7.2.8, 7.0.0 to 7.0.15, 6.4.0 to 6.4.15), FortiProxy (versions 7.4.0 to 7.4.4, 7.2.0 to 7.2.10, 7.0.0 to 7.0.17, 2.0.0 to 2.0.14), FortiManager (versions 7.6.0 to 7.6.1, 7.4.1 to 7.4.3) and FortiAnalyzer Cloud (versions 7.4.1 to 7.4.3). The vulnerability arises from weak authentication, allowing attackers to execute unauthorized code or commands through brute-force attacks.
Fortinet FortiManager, FortiOS, and FortiProxy Path Traversal Vulnerability Allowing Privilege Escalation
A path traversal vulnerability has been identified in Fortinet FortiManager versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiOS versions 7.6.0, 7.4.0 through 7.4.4, 7.2.5 through 7.2.9, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15, and FortiProxy versions 7.4.0 through 7.4.5, 7.2.0 through 7.2.11, 7.0.0 through 7.0.18, 2.0.0 through 2.0.14, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, and 1.0.0 through 1.0.7. This vulnerability allows attackers to escalate privileges by sending specially crafted packets, exploiting improper restrictions on file paths that could lead to unauthorized access to restricted directories.
Fortinet FortiSOAR CSV File Formula Injection Vulnerability Allowing Unauthorized Code Execution
A vulnerability exists in Fortinet FortiSOAR versions 7.2.1 through 7.4.1, due to improper handling of formula elements in CSV files. This flaw enables attackers to execute unauthorized code or commands by manipulating the CSV file.
Fortinet FortiManager Improper Access Control Vulnerability in FortiGate via Valid Credentials
A vulnerability allowing improper access control has been identified in Fortinet FortiManager versions 6.4.12 through 7.4.0. This vulnerability arises from an operation on a resource after its expiration or release, which can allow an attacker to gain unauthorized access to FortiGate using valid credentials. Specifically, an admin account deleted through FortiManager may still be able to log into FortiGate.
Fortinet FortiRecorder Path Traversal Vulnerability Allowing File Deletion
A path traversal vulnerability has been identified in Fortinet FortiRecorder versions 7.2.0 through 7.2.1 and prior to 7.0.4. This vulnerability allows a privileged attacker to delete files from the underlying filesystem by sending crafted CLI requests. The issue arises from an improper restriction of pathname limitations, enabling unauthorized file deletion.
Fortinet FortiOS Out-of-Bounds Read Vulnerability Leading to Denial-of-Service
A vulnerability allowing out-of-bounds read has been identified in Fortinet FortiOS versions 7.6.0, 7.4.4 and below, 7.2.9 and below, as well as in FortiSASE FortiOS tenant version 24.3.b. This vulnerability may allow an unauthenticated remote attacker to send crafted requests that trigger excessive memory consumption, leading to a denial-of-service condition.
Fortinet FortiOS and FortiSASE Integer Overflow Vulnerability in IPsec IKE Service Allowing Denial-of-Service
A vulnerability allowing integer overflow or wraparound has been identified in Fortinet FortiOS versions 7.4.0 through 7.4.4, and 7.2.0 through 7.2.10, as well as FortiSASE version 23.4.b. This vulnerability exists in the FortiOS tenant IPsec IKEv1 service, where an authenticated attacker can send crafted requests to crash the IPsec tunnel, leading to a potential denial-of-service condition.
Fortinet FortiOS Resource Exhaustion Vulnerability via Unauthenticated Large File Uploads
A vulnerability allowing resource exhaustion through unlimited large file uploads has been identified in Fortinet FortiOS. This issue affects versions 7.4.0 to 7.4.4, 7.2.0 to 7.2.8, 7.0.0 to 7.0.15, and 6.4.0 to 6.4.15. The vulnerability could enable an unauthenticated remote user to deplete all system memory, potentially leading to a denial of service.
Fortinet FortiSIEM Resource Exhaustion Vulnerability Leading to TLS Denial-of-Service
A denial-of-service vulnerability has been identified in Fortinet FortiSIEM versions 5.3, 5.4, 6.x, 7.0, and 7.1.0 through 7.1.5. This vulnerability arises from an unlimited allocation of resources, allowing an attacker to consume all available connections and disrupt valid TLS traffic.
Fortinet FortiOS Denial-of-Service Vulnerability via Unauthenticated Requests to GUI Endpoints
A denial-of-service vulnerability has been identified in Fortinet FortiOS. This issue affects versions 7.6.0, 7.4.4 through 7.4.0, 7.2 (all versions), 7.0 (all versions), and 6.4 (all versions). The vulnerability arises from an allocation of resources without limits or throttling, allowing remote unauthenticated attackers to disrupt access to the graphical user interface (GUI) by sending specially crafted requests to specific endpoints.
Fortinet FortiOS RADIUS Accounting Server Shared Secret Exposure Vulnerability
A vulnerability allowing the insertion of sensitive information into transmitted data has been identified in Fortinet FortiOS versions 7.6.0 and 7.4.0 through 7.4.4. This vulnerability may enable an attacker in a man-in-the-middle position to intercept accounting requests and retrieve the shared secret used for RADIUS accounting server communications.
Fortinet FortiRecorder Relative Path Traversal Vulnerability Allowing File Read
A relative path traversal vulnerability has been identified in Fortinet FortiRecorder versions 7.2.0 through 7.2.1 and prior to 7.0.4. This vulnerability allows a privileged attacker to read files from the underlying filesystem by sending crafted HTTP or HTTPS requests.
Fortinet FortiDeceptor Improper Access Control Vulnerability Allowing Unauthorized Operations on Central Management Appliance
A vulnerability allowing improper access control has been identified in Fortinet FortiDeceptor versions 6.0.0, 5.3.3 and below, 5.2.1 and below, 5.1.0, and 5.0.0. This vulnerability may enable an authenticated attacker with no privileges to execute operations on the central management appliance by sending crafted requests.
Fortinet FortiVoice OS Command Injection Vulnerability Allowing Unauthorized Code Execution
A vulnerability allowing OS command injection has been identified in Fortinet FortiVoice versions 7.0.0 through 7.0.4 and prior to 6.4.9. This vulnerability arises from improper neutralization of special elements used in OS commands, allowing an authenticated privileged attacker to execute unauthorized code or commands through crafted CLI requests.
Fortinet FortiManager and FortiAnalyzer Path Traversal Vulnerability Allowing Unauthorized Code Execution
A path traversal vulnerability has been identified in Fortinet FortiManager and FortiAnalyzer versions 7.4.0 to 7.4.3, 7.2.0 to 7.2.5, 7.0.2 to 7.0.12, and 6.2.10 to 6.2.13. This vulnerability arises from an improper restriction of file paths, allowing attackers to execute unauthorized code or commands by sending crafted HTTP or HTTPS requests.
Fortinet FortiClient and FortiSOAR User Enumeration Vulnerability
A vulnerability allowing user enumeration through response timing discrepancies has been identified in Fortinet FortiClient EMS versions 7.4.0, 7.2.0 prior to 7.2.4, 7.0 all versions, and Fortinet FortiSOAR versions 7.5.0, 7.4.0 prior to 7.4.4, 7.3.0 prior to 7.3.2, 7.2 all versions, 7.0 all versions, and 6.4 all versions. This vulnerability allows an unauthenticated attacker to identify valid users by analyzing the differences in login request responses.
Fortinet FortiClient EMS Improper Verification of Communication Source Vulnerability Allowing Trusted Host Bypass
A vulnerability allowing for improper verification of the source of a communication channel has been identified in Fortinet FortiClient EMS versions 7.4.0, 7.2.0 through 7.2.4, 7.0 (all versions), and 6.4 (all versions). This vulnerability may enable a remote attacker to bypass the trusted host feature by manipulating session connections.
Fortinet FortiOS SSLVPN Web Portal Out-of-Bounds Read Vulnerability Leading to Denial-of-Service
A denial-of-service vulnerability has been identified in the FortiOS SSLVPN web portal. This issue arises from an out-of-bounds read vulnerability, allowing an authenticated attacker to disrupt the SSLVPN web portal's functionality. The vulnerability is present in FortiOS SSLVPN web portal versions 7.4.0 to 7.4.4, 7.2.0 to 7.2.8, all versions of 7.0, and all versions of 6.4. The issue can be exploited by sending a specially crafted URL to the SSLVPN web portal.
Fortinet FortiPortal SQL Injection Vulnerability Allowing Query Disclosure
A SQL injection vulnerability has been identified in Fortinet FortiPortal versions 7.2.4 through 7.2.0 and 7.0.0 through 7.2.8. This vulnerability arises from improper neutralization of special elements used in SQL commands, which may allow an authenticated attacker to view SQL queries being executed on the server side. The issue can be exploited by including special elements in an HTTP request.
Fortinet FortiPortal and FortiManager Missing Authentication Vulnerability in Critical Function
A vulnerability allowing unauthorized access to the configuration of managed devices has been identified in Fortinet FortiPortal versions 6.0.0 to 6.0.15 and FortiManager versions 7.4.0 to 7.4.2, 7.2.0 to 7.2.5, 7.0.0 to 7.0.12, and 6.4.0 to 6.4.14. This vulnerability arises from a missing authentication for critical functions, enabling attackers to access device configurations by sending specially crafted packets.
Fortinet FortiAnalyzer, FortiManager, FortiManager Cloud, and FortiAnalyzer Cloud Stack-Based Buffer Overflow Vulnerability Allowing Unauthorized Code Execution
A stack-based buffer overflow vulnerability has been identified in Fortinet FortiAnalyzer, FortiManager, FortiManager Cloud, and FortiAnalyzer Cloud. This vulnerability affects multiple versions within the FortiAnalyzer and FortiManager product lines, as well as their cloud counterparts. The issue allows attackers to execute unauthorized code or commands by sending specially crafted packets.
Fortinet FortiAnalyzer and FortiManager SQL Injection Vulnerability Allowing Privilege Escalation
A SQL injection vulnerability has been identified in Fortinet FortiAnalyzer versions 7.4.0 to 7.4.2 and FortiManager versions 7.4.0 to 7.4.2. This vulnerability arises from improper neutralization of special elements used in SQL commands, allowing attackers to escalate privileges by sending specially crafted HTTP requests.
Fortinet FortiManager and FortiAnalyzer Privilege Escalation Vulnerability
A vulnerability allowing out-of-bounds write has been identified in Fortinet FortiManager versions 7.4.0 to 7.4.2 and FortiAnalyzer versions 7.4.0 to 7.4.2. This vulnerability allows attackers to escalate privileges by sending specially crafted HTTP requests.
Fortinet FortiManager and FortiAnalyzer Privilege Escalation Vulnerability
A vulnerability allowing privilege escalation through specific shell commands has been identified in Fortinet FortiManager and FortiAnalyzer. This issue affects multiple versions: FortiManager versions 7.4.0 to 7.4.3, 7.2.0 to 7.2.5, 7.0.0 to 7.0.12, and 6.4.0 to 6.4.14. FortiAnalyzer versions 7.4.0 to 7.4.2, 7.2.0 to 7.2.5, 7.0.0 to 7.0.12, and 6.4.0 to 6.4.14 are also affected.
Fortinet FortiManager and FortiAnalyzer Path Traversal Vulnerability Allowing Unauthorized Code Execution
A path traversal vulnerability has been identified in Fortinet FortiManager and FortiAnalyzer. Affected versions include FortiManager and FortiAnalyzer 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, 6.2.0 through 6.2.12, and 6.0.0 through 6.0.12. This vulnerability allows attackers to execute unauthorized code or commands by sending crafted HTTP or HTTPS requests that exploit the improper limitation of pathnames to restricted directories.
Fortinet FortiManager Relative Path Traversal Vulnerability Allowing File Deletion
A relative path traversal vulnerability has been identified in Fortinet FortiManager versions 7.4.0 through 7.4.2 and prior to 7.2.5. This vulnerability allows a privileged attacker to delete files from the underlying filesystem by sending crafted HTTP or HTTPS requests.
