CVE-2021-22126 Details
Description
A use of hard-coded password vulnerability in FortiWLC version 8.5.2 and below, version 8.4.8 and below, version 8.3.3 to 8.3.2, version 8.2.7 to 8.2.6 may allow a local, authenticated attacker to connect to the managed Access Point (Meru AP and FortiAP-U) as root using the default hard-coded username and password.
A vulnerability exists in Fortinet FortiWLC versions 8.5.2 and prior, 8.4.8 and prior, 8.3.3 to 8.3.2, and 8.2.7 to 8.2.6. This vulnerability involves the use of hard-coded passwords, which may enable a local, authenticated attacker to connect to managed Access Points (Meru AP and FortiAP-U) as root, using the default hard-coded username and password.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 18, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-20-147 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-798 | Use of Hard-coded Credentials | [email protected] |
| CWE-284 | Improper Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| fortinet fortiwlc | >= 8.4.0, < 8.5.3 8.2.6 8.2.7 8.3.2 8.3.3 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 24, 2025 | Initial Analysis | [email protected] |
| Mar 17, 2025 | New CVE Received | [email protected] |