> Path traversal in CLI command allows deletion of root file system
[DATE: 14/07/2026 07:00]
[LANGUAGE: EN]
CVSSv3 Score:
5.0
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiOS, FortiPAM, FortiProxy and FortiSwitch Manager may allow a privileged authenticated attacker with physical access to the device to delete the file system via crafted CLI commands.
Revised on 2026-07-14 00:00:00