S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jun 26, 2025

CVE-2021-22123 Scanner

CVE-2021-22123 Scanner - OS Command Injection vulnerability in FortiWeb

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.4k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
CVECVE-2021-22123
8.8
CVSShigh
Exploitable remotely over the internet · low-privilege account sufficient.

An OS command injection vulnerability in FortiWeb's management interface 6.3.7 and below, 6.2.3 and below, 6.1.x, 6.0.x, 5.9.x may allow a remote authenticated attacker to execute arbitrary commands on the system via the SAML server configuration page.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
Fortinet FortiWebby Fortinet
FortiWeb 6.3.7 and below, 6.2.3 and below, 6.1.x, 6.0.x, 5.9.x
Updated Aug 21, 2026View on NVD →
Detail

FortiWeb is a comprehensive web application firewall (WAF) solution used by organizations globally to secure their web-based applications. It provides advanced security features, including protection against known vulnerabilities and zero-day threats. FortiWeb is extensively used by medium to large enterprises and service providers to safeguard sensitive web interactions. The software is particularly crucial in environments where data protection, regulatory compliance, and threat prevention are high priorities. Designed to integrate seamlessly with an organization's infrastructure, FortiWeb offers capabilities like IP reputation, web filtering, and traffic log management. It is a crucial tool to ensure secure and efficient business operations online.

The OS Command Injection vulnerability allows attackers to execute arbitrary commands on a vulnerable system. In FortiWeb's management interface, when SAML server configuration is improperly handled, it can result in unauthorized command execution. An attacker exploiting this flaw could gain a foothold in the target system, potentially compromising system integrity. The vulnerability primarily affects versions up to 6.3. Consequently, it enables remote attackers to perform actions with the same privileges as the application itself, extending the attack impact. Organizations running affected versions face significant risks from this exploitable loophole.

Technical details of this vulnerability involve the SAML server configuration page within FortiWeb's internal management interface. The endpoint in question processes multipart form-data where command injection can be introduced via the 'name' parameter. A typical attack vector would involve crafting a payload that exploits this endpoint to execute system commands. The form submission processes input in a way that does not adequately sanitize or validate the injected content, leading to command execution. Attackers can submit malicious configurations that effectively use existing permissions to run unauthorized operations. This flaw underscores the importance of input validation and sanitization in web applications.

Exploitation of this vulnerability can have severe consequences on affected systems, such as unauthorized access, data breach, and system compromise. Malicious actors gaining command execution capabilities can manipulate the system to launch further attacks or extract sensitive information. The implications include loss of data integrity, potential legal ramifications depending on data accessed, and operational disruption. An organization’s reputation can suffer significantly upon disclosure of such a vulnerability being exploited. Effective exploitation can lead to persistence on the system, making remediation and cleanup efforts more challenging.

REFERENCES

Solution Advice
  • Upgrade FortiWeb to the latest version that addresses this vulnerability.
  • Restrict SAML configurations to trusted administrators only.
  • Implement comprehensive logging and monitoring of management interface access.
  • Regularly review and audit SAML configurations to identify unauthorized changes.
  • Ensure robust input validation and command sanitization in web application components.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-22123 Scanner - OS Command Injection vulnerability in FortiWeb | S4E