← Back to browse · API

CVE-2021-26102

Severity
CRITICAL
CVSS
9.8
EPSS
0.16761
Risk score
45.07
CISA KEV
No
PoC
No
Published
2024-12-19
Modified
2024-12-19
First seen
2026-08-07
Aliases
EUVD-2021-12923, GHSA-WWQ6-XMJH-4F52
Products
Fortinet:FortiWAN 4.4.0 ≤4.4.1, Fortinet:FortiWAN 4.5.0 ≤4.5.7
Sources
euvd EUVD-2021-12923

Description

A relative path traversal vulnerability (CWE-23) in FortiWAN version 4.5.7 and below, 4.4 all versions may allow a remote non-authenticated attacker to delete files on the system by sending a crafted POST request. In particular, deleting specific configuration files will reset the Admin password to its default value.

References