A use of hard-coded password vulnerability in FortiWLC...
Moderate severity
Unreviewed
Published
Mar 17, 2025
to the GitHub Advisory Database
•
Updated Jul 24, 2025
Description
Published by the National Vulnerability Database
Mar 17, 2025
Published to the GitHub Advisory Database
Mar 17, 2025
Last updated
Jul 24, 2025
A use of hard-coded password vulnerability in FortiWLC version 8.5.2 and below, version 8.4.8 and below, version 8.3.3 to 8.3.2, version 8.2.7 to 8.2.6 may allow a local, authenticated attacker to connect to the managed Access Point (Meru AP and FortiAP-U) as root using the default hard-coded username and password.
References