CVE-2016-7560: Fortinet Fortiwlc

Critical severity, CVSS 9.8. EPSS: 2.7% chance of exploitation in the next 30 days.

The rsyncd server in Fortinet FortiWLC 6.1-2-29 and earlier, 7.0-9-1, 7.0-10-0, 8.0-5-0, 8.1-2-0, and 8.2-4-0 has a hardcoded rsync account, which allows remote attackers to read or write to arbitrary files via unspecified vectors.

Affected products

  • Fortinet Fortiwlc: up to and including 6.1-2-29; version 7.0-9-1 only; version 7.0-10-0 only; version 8.0-5-0 only; version 8.1-2-0 only; version 8.2-4-0 only

Published 2016-10-05. Last modified 2026-06-17.