CVE-2023-36634: Fortinet Fortiap-U

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpreter of FortiAP-U 7.0.0, 6.2.0 through 6.2.5, 6.0 all versions, 5.4 all versions may allow an authenticated attacker to list and delete arbitrary files and directory via specially crafted command arguments.

Affected products

  • Fortinet Fortiap-U: from 5.4.0, up to and including 5.4.6; from 6.0.0, up to and including 6.0.4; from 6.2.0, up to and including 6.2.5; version 7.0.0 only

Published 2023-09-13. Last modified 2026-06-17.