CVE-2023-34990
moderateUnauthenticated Path Traversal to Code Execution in Fortinet FortiWLM
CVE-2023-34990 is a relative path traversal (CWE-23) in Fortinet's Wireless LAN Manager (FortiWLM) that allows attackers to execute unauthorized code or commands. It is triggered by specially crafted web requests sent to the management interface, and the CVSS vector (network, low complexity, no privileges, no user interaction) indicates unauthenticated remote exploitation. Successful exploitation yields full command execution on the appliance, and related reporting suggests it can lead to administrator-level access on affected systems. Any organization running FortiWLM 8.6.0 through 8.6.5 or 8.5.0 through 8.5.4 is affected. There is no known public proof-of-concept and the flaw is not yet in CISA's KEV, but the 24.9% EPSS score (98th percentile) indicates a high predicted likelihood of exploitation attempts within 30 days.
What to do: Upgrade FortiWLM to a release outside the affected ranges — i.e., later than 8.6.5 on the 8.6 branch or later than 8.5.4 on the 8.5 branch — per Fortinet's advisory. Until patched, restrict access to the FortiWLM web management interface to trusted networks or VPN users and do not expose it directly to the internet. Check device logs for unexpected or anomalous web requests targeting the manager, and prioritize patching internet-facing instances given the high EPSS score.
| Fortinet FortiWLM | 8.6.0 through 8.6.5 |
| Fortinet FortiWLM | 8.5.0 through 8.5.4 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specially crafted web requests.
- Vendors
- fortinet
- Products
- fortiwlm
- Weakness
- CWE-23, CWE-94
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H