Fortinet / FortiWLC
14 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2021-22126 | A use of hard-coded password vulnerability in FortiWLC version 8.5.2 and below, version 8.4.8 and below, version 8.3.3 to 8.3.2, version 8.2.7 to 8.2.6 may all… | MEDIUM | 6.7 | Mar 17, 2025 |
| CVE-2021-32584 | An improper access control (CWE-284) vulnerability in FortiWLC version 8.6.0, version 8.5.3 and below, version 8.4.8 and below, version 8.3.3 and below, versio… | MEDIUM | 5.3 | Mar 17, 2025 |
| CVE-2021-26087 | An improper neutralization of input during web page generation in FortiWLC version 8.6.0, version 8.5.3 and below, version 8.4.8 and below, version 8.3.3 web i… | MEDIUM | 6.1 | Mar 17, 2025 |
| CVE-2022-23439 | A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, whe… | MEDIUM | 6.1 | Jan 22, 2025 |
| CVE-2021-26093 | An access of uninitialized pointer (CWE-824) vulnerability in FortiWLC versions 8.6.0, 8.5.3 and earlier may allow a local and authenticated attacker to crash… | MEDIUM | 6.6 | Dec 19, 2024 |
| CVE-2021-42758 | An improper access control vulnerability [CWE-284] in FortiWLC 8.6.1 and below may allow an authenticated and remote attacker with low privileges to execute an… | HIGH | 8.8 | Dec 8, 2021 |
| CVE-2020-9288 | An improper neutralization of input vulnerability in FortiWLC 8.5.1 allows a remote authenticated attacker to perform a stored cross site scripting attack (XSS… | MEDIUM | 5.4 | Jun 22, 2020 |
| CVE-2017-17540 | The presence of a hardcoded account in Fortinet FortiWLC 8.3.3 allows attackers to gain unauthorized read/write access via a remote shell. | CRITICAL | 9.8 | May 7, 2018 |
| CVE-2017-17539 | The presence of a hardcoded account in Fortinet FortiWLC 7.0.11 and earlier allows attackers to gain unauthorized read/write access via a remote shell. | CRITICAL | 9.8 | May 7, 2018 |
| CVE-2017-7341 | An OS Command Injection vulnerability in Fortinet FortiWLC 6.1-2 through 6.1-5, 7.0-7 through 7.0-10, 8.0 through 8.2, and 8.3.0 through 8.3.2 file management… | HIGH | 7.2 | Oct 26, 2017 |
| CVE-2017-7335 | A Cross-Site Scripting (XSS) vulnerability in Fortinet FortiWLC 6.1-x (6.1-2, 6.1-4 and 6.1-5); 7.0-x (7.0-7, 7.0-8, 7.0-9, 7.0-10); and 8.x (8.0, 8.1, 8.2 and… | MEDIUM | 5.4 | Oct 26, 2017 |
| CVE-2016-8491 | The presence of a hardcoded account named 'core' in Fortinet FortiWLC allows attackers to gain unauthorized read/write access via a remote shell. | CRITICAL | 9.1 | Feb 1, 2017 |
| CVE-2016-7561 | Fortinet FortiWLC 6.1-2-29 and earlier, 7.0-9-1, 7.0-10-0, 8.0-5-0, 8.1-2-0, and 8.2-4-0 allow administrators to obtain sensitive user credentials by reading t… | HIGH | 7.2 | Oct 5, 2016 |
| CVE-2016-7560 | The rsyncd server in Fortinet FortiWLC 6.1-2-29 and earlier, 7.0-9-1, 7.0-10-0, 8.0-5-0, 8.1-2-0, and 8.2-4-0 has a hardcoded rsync account, which allows remot… | CRITICAL | 9.8 | Oct 5, 2016 |
Showing 1 to 14 of 14 CVEs