CVE-2023-40716: Fortinet Fortitester

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

An improper neutralization of special elements used in an OS command vulnerability [CWE-78]  in the command line interpreter of FortiTester 2.3.0 through 7.2.3 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments when running execute restore/backup .

Affected products

  • Fortinet Fortitester: version 2.3.0 only; version 2.4.0 only; version 2.4.1 only; version 2.5.0 only; version 2.6.0 only; version 2.7.0 only; …

Published 2023-12-13. Last modified 2026-06-17.