CVE-2016-8491: Fortinet Fortiwlc

Critical severity, CVSS 9.1. EPSS: 1.5% chance of exploitation in the next 30 days.

The presence of a hardcoded account named 'core' in Fortinet FortiWLC allows attackers to gain unauthorized read/write access via a remote shell.

Affected products

  • Fortinet Fortiwlc: version 7.0-9-1 only; version 7.0-10-0 only; version 8.1-2-0 only; version 8.1-3-2 only; version 8.2-4-0 only

Published 2017-02-01. Last modified 2026-06-17.