CVE-2022-33872: Fortinet Fortitester

Critical severity, CVSS 9.8. EPSS: 3% chance of exploitation in the next 30 days.

An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in Telnet login components of FortiTester 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated remote attacker to execute arbitrary command in the underlying shell.

Affected products

  • Fortinet Fortitester: from 2.3.0, before 3.9.2 (fixed in 3.9.2); from 4.0.0, before 4.2.1 (fixed in 4.2.1); from 7.0.0, before 7.1.1 (fixed in 7.1.1)

Published 2022-10-18. Last modified 2026-06-17.