Medium SEVERITY — Vulnerability

Path traversal in CLI command allows deletion of root file system

CVSSv3 Score: 5.0 An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiOS, FortiPAM, FortiProxy and FortiSwitch Manager may allow a privileged authenticated attacker with physical access to the device to delete the file system via crafted CLI commands. Revised on 2026-07-14 00:00:00

Platform
FortiGate / FortiOS
CVSS Score
5.0/10
Advisory
FG-IR-26-151
Published
14 July 2026
Views
3
Primary source: Review the official advisory at fortiguard.fortinet.com Kaynağa Git

Summary

CVSSv3 Score: 5.0 An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiOS, FortiPAM, FortiProxy and FortiSwitch Manager may allow a privileged authenticated attacker with physical access to the device to delete the file system via crafted CLI commands. Revised on 2026-07-14 00:00:00

Source

  • [Open vendor advisory](https:\/\/fortiguard.fortinet.com\/psirt\/FG-IR-26-151)

This record was automatically ingested; verify the content before publishing.

FortiGate / FortiOS — Related Advisories

VIEW ALL →