PT-2025-11479 · Fortinet · Fortiwlc

Published

2025-03-17

·

Updated

2025-03-17

·

CVE-2021-22126

CVSS v3.1

6.7

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FortiWLC versions 8.5.2 and below FortiWLC versions 8.4.8 and below FortiWLC versions 8.3.3 through 8.3.2 FortiWLC versions 8.2.7 through 8.2.6
Description A use of hard-coded password issue may allow a local, authenticated attacker to connect to the managed Access Point as root using the default hard-coded username and password.
Recommendations For FortiWLC versions 8.5.2 and below, update to a version above 8.5.2 to resolve the issue. For FortiWLC versions 8.4.8 and below, update to a version above 8.4.8 to resolve the issue. For FortiWLC versions 8.3.3 through 8.3.2, update to a version above 8.3.3 to resolve the issue. For FortiWLC versions 8.2.7 through 8.2.6, update to a version above 8.2.7 to resolve the issue. As a temporary workaround, consider changing the default hard-coded username and password to minimize the risk of exploitation.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-22126

Affected Products

Fortiwlc