Known vulnerabilities in FortiExtender

Software: FortiExtender
Software CPE: cpe:2.3:h:fortinet:fortiextender:*:*:*:*:*:*:*:*
Total vulnerabilities: 9
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.2

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting FortiExtender FortiExtender is affected by 9 known vulnerabilities: 1 high, 2 medium, 6 low Critical High Medium Low

Vulnerabilities (9)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU119444 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-64153
CWE-78 Low
No
No
7.4.8, 7.6.4 09.12.2025 SB2025120955
#VU118601 - Insufficiently Protected Credentials
CVE-2025-46775
CWE-522 Low
No
No
7.4.8, 7.6.3 18.11.2025 SB2025111870
#VU118600 - Buffer overflow
CVE-2025-46776
CWE-120 Low
No
No
7.4.8, 7.6.3 18.11.2025 SB2025111869
#VU94002 - Improper Access Control
CVE-2024-23663
CWE-284 Medium
No
No
7.0.5, 7.2.5, 7.4.3 09.07.2024 SB20240709109
#VU93513 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2024-6387
CWE-362 High
Available
No
7.0.6, 7.2.6, 7.4.6 01.07.2024 SB2024070144
SB2024070145
SB2024070152
and 89 more
#VU84868 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2022-23447
CWE-22 Medium
No
No
3.2.4, 3.3.3, 4.0.3, 4.1.9, 4.2.5, 7.0.4 29.12.2023 SB2023122911
#VU72364 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-27489
CWE-78 Low
No
No
3.2.4, 3.3.3, 7.0.4, 7.2.0 17.02.2023 SB2023021737
#VU60215 - Command injection
CVE-2021-41016
CWE-77 Low
No
No
4.1.8, 4.2.4, 7.0.2 01.02.2022 SB2022020173
#VU22314 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2019-15710
CWE-78 Low
No
No
4.1.2 29.10.2019 SB2019102901