CVE-2016-4965: Fortinet Fortiwan
High severity, CVSS 8.8. EPSS: 4.1% chance of exploitation in the next 30 days.
Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users with access to the nslookup functionality to execute arbitrary commands with root privileges via the graph parameter to diagnosis_control.php.
Affected products
- Fortinet Fortiwan: up to and including 4.2.4
Published 2016-09-21. Last modified 2026-06-17.