A vulnerability has been discovered in FortiWAN which could allow for arbitrary code execution. FortiWAN is a product that balances traffic over multiple WAN connections. Successful exploitation of this vulnerability could allow an unauthenticated attacker to execute arbitrary code using specially crafted requests.
SYSTEMS AFFECTED:
RISK:
Government:
Businesses:
Home users: Low
TECHNICAL SUMMARY:
A vulnerability has been discovered in FortiWAN which could allow for arbitrary code execution. Stack-based buffer overflow vulnerabilities in in network daemons and in the command line interpreter of FortiWAN may allow an unauthenticated attacker to potentially corrupt control data in memory and execute arbitrary code via specifically crafted requests. Successful exploitation of this vulnerability could result in arbitrary code execution.
RECOMMENDATIONS:
We recommend the following actions be taken:
REFERENCES:
Fortiguard:
https://www.fortiguard.com/psirt/FG-IR-21-065
CVE:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-26112