Path traversal in CLI command allows deletion of root file system
Path traversal vulnerability in CLI command input validation allows authenticated high-privilege users to bypass file access restrictions and delete arbitrary files on the device using directory traversal sequences. Exploitation could delete critical system files and render the device inoperable. The vulnerability affects multiple FortiOS, FortiPAM, and FortiProxy product lines across various versions. Affected products include FortiOS 7.0–7.6, FortiPAM 1.6–1.8, and FortiProxy 7.0–7.6. Several product versions have no patch available and require migration to fixed releases.
- High-privilege (administrator) credentials for CLI access
- Direct or proxied access to the device's command-line interface (SSH, console, or remote management port)
- Knowledge of critical file system paths on the target device
Patching may require device reboot — plan for process interruption
/api/v1/advisories/29156294-909d-4ee6-b18f-9b6ba0c71660Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.