Home/Product/fortinet fortiap w2
Product

fortinet fortiap w2

9 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-53870
>= 7.2.0 and < 7.2.6
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiAP 7.
6.7MEDIUM
CVE-2025-53680
>= 7.2.0 and < 7.4.5
An improper neutralization of special elements used in an OS command ("OS Command Injection") vulnerability [CWE-78] vulnerability
6.7MEDIUM
CVE-2024-26012
>= 6.4.0 and < 7.2.4
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiAP-S 6.2 all verison
6.7MEDIUM
CVE-2023-25608
>= 6.0.0 and <= 7.0.1
An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpreter of Fo
5.5MEDIUM
CVE-2022-29058
>= 6.0.0 and <= 6.0.6
An improper neutralization of special elements [CWE-89] used in an OS command vulnerability [CWE-78] in the command line interpret
7.8HIGH
CVE-2021-26106
>= 6.2.4 and < 6.2.6
An improper neutralization of special elements used in an OS Command vulnerability in FortiAP's console 6.4.1 through 6.4.5 and 6.
7.8HIGH
CVE-2019-15709
<= 6.0.5
An improper input validation in FortiAP-S/W2 6.2.0 to 6.2.2, 6.0.5 and below, FortiAP-U 6.0.1 and below CLI admin console may allo
6.5MEDIUM
CVE-2019-17657
< 6.2.2
An Uncontrolled Resource Consumption vulnerability in Fortinet FortiSwitch below 3.6.11, 6.0.6 and 6.2.2, FortiAnalyzer below 6.2.
7.5HIGH
CVE-2019-15708
<= 6.0.5
A system command injection vulnerability in the FortiAP-S/W2 6.2.1, 6.2.0, 6.0.5 and below, FortiAP 6.0.5 and below and FortiAP-U
6.7MEDIUM
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin