CVE detail
CVE-2021-22126 — CVE-2021-22126
Published 2025-03-17 · Modified 2026-06-17 · Vendor fortinet · Product fortiwlc · Source nvd
MEDIUM
severity
CVSS-derived band
0.0016
EPSS probability
exploitation probability, 30d
5.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
A use of hard-coded password vulnerability in FortiWLC version 8.5.2 and below, version 8.4.8 and below, version 8.3.3 to 8.3.2, version 8.2.7 to 8.2.6 may allow a local, authenticated attacker to connect to the managed Access Point (Meru AP and FortiAP-U) as root using the default hard-coded username and password.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References