Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-71407

Опубликовано: 12 авг. 2026
Источник: nvd
CVSS3: 5.6
CVSS3: 8.1
EPSS Низкий

Описание

A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands in the context of the WAD daemon via crafted sockets, only if the explicit proxy is configured with Kerberos authentication and SOCKS enabled.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
Версия от 7.6.1 (включая) до 7.6.7 (исключая)

EPSS

Процентиль: 44%
0.0054
Низкий

5.6 Medium

CVSS3

8.1 High

CVSS3

Дефекты

CWE-121

Связанные уязвимости

CVSS3: 5.6
github
около 1 месяца назад

A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands in the context of the WAD daemon via crafted sockets, only if the explicit proxy is configured with Kerberos authentication and SOCKS enabled.

CVSS3: 5.6
fstec
около 1 месяца назад

Уязвимость демона WAD (Web Access Daemon) операционных систем FortiOS, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 44%
0.0054
Низкий

5.6 Medium

CVSS3

8.1 High

CVSS3

Дефекты

CWE-121