CVE-2023-25608
An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpreter of FortiAP-W2 7.2.0 through 7.2.1, 7.0.3 through 7.0.5, 7.0.0 through 7.0.1, 6.4 all versions, 6.2 all versions, 6.0 all versions; FortiAP-C 5.4.0 through 5.4.4, 5.2 all versions; FortiAP 7.2.0 through 7.2.1, 7.0.0 through 7.0.5, 6.4 all versions, 6.0 all versions; FortiAP-U 7.0.0, 6.2.0 through 6.2.5, 6.0 all versions, 5.4 all versions may allow an authenticated attacker to read arbitrary files via specially crafted command arguments.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.2
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:P/RL:U/RC:C
- EPSS probability
- 0.23%
- CWE
- CWE-792
- Published
- 2023-09-13
- Last modified
- 2026-03-13
Affected products
- Fortinet FortiAP-W2
- Fortinet FortiAP-W2
- Fortinet FortiAP-W2
- Fortinet FortiAP-W2
- Fortinet FortiAP-W2
- Fortinet FortiAP-W2
- Fortinet FortiAP-C
- Fortinet FortiAP-C
Weakness type
Related vulnerabilities
- CVE-2025-12758 — Versions of the package validator before 13.15.22 are vulnerable to Incomplete Filtering of One or...
- CVE-2025-47779 — Using malformed From header can forge identity with ";" or NULL in name portion
- CVE-2022-22297 — An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the...
- CVE-2023-20057 — A vulnerability in the URL filtering mechanism of Cisco AsyncOS Software for Cisco Email Security...