Hardcoded 'core' Account in Fortinet FortiWLC Allows Unauthorized Remote Shell Access

Hardcoded 'core' Account in Fortinet FortiWLC Allows Unauthorized Remote Shell Access

CVE-2016-8491 · HIGH Severity

AV:N/AC:L/AU:N/C:C/I:C/A:N

The presence of a hardcoded account named 'core' in Fortinet FortiWLC allows attackers to gain unauthorized read/write access via a remote shell.

Learn more about our Cis Benchmark Audit For Fortinet.