Vulnerability record · CVE-2021-3378 · published 1 February 2021
CVE-2021-3378: FortiLogger unrestricted file upload via logo endpoint
Fortilogger · Fortilogger
FortiLogger 4.4.2.2 allows an unauthenticated attacker to upload arbitrary files through the Config/SaveUploadedHotspotLogoFile endpoint by spoofing a Content-Type: image/png header. The uploaded file is then reachable at Assets/temp/hotspot/img/logohotspot.asp, so a crafted upload can be executed as server-side code. This is a critical pre-auth remote code execution path in the affected version.
Description
FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUploadedHotspotLogoFile and then visiting Assets/temp/hotspot/img/logohotspot.asp.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable arbitrary file upload with public exploit code and a 9.8 CVSS score allows full server compromise.
What it is
FortiLogger 4.4.2.2 allows an unauthenticated attacker to upload arbitrary files through the Config/SaveUploadedHotspotLogoFile endpoint by spoofing a Content-Type: image/png header. The uploaded file is then reachable at Assets/temp/hotspot/img/logohotspot.asp, so a crafted upload can be executed as server-side code. This is a critical pre-auth remote code execution path in the affected version.
Impact
An attacker can place and execute arbitrary code on the FortiLogger host, leading to full compromise of the application and its underlying server. Because the request is unauthenticated, no credentials are needed to reach that outcome.
Attack surface
The flaw is reached over the network through the Config/SaveUploadedHotspotLogoFile upload endpoint, with the uploaded payload later requested from Assets/temp/hotspot/img/logohotspot.asp. The CVSS vector shows no privileges and no user interaction required, so it is remotely reachable without authentication.
Exploitation
Public exploit code is available via Packet Storm and a GitHub repository, and EPSS is very high (0.97512, 99.9th percentile), indicating likely exploitation activity. CISA KEV does not list this CVE.
What to do
- Upgrade FortiLogger past 4.4.2.2 to a fixed release; the record does not name a patched version, so confirm with the vendor.
- If upgrade is not possible, restrict network access to the FortiLogger web interface to trusted management networks only.
- Block or remove execution rights on the Assets/temp/hotspot/img/ directory and reject uploads that do not match expected image content.
- Add server-side validation that verifies actual file content, not just the client-supplied Content-Type header.
- Monitor and alert on requests to Config/SaveUploadedHotspotLogoFile and on access to Assets/temp/hotspot/img/logohotspot.asp.
Detection
- Search web logs for POST requests to Config/SaveUploadedHotspotLogoFile, especially with Content-Type: image/png and non-image payloads.
- Alert on GET requests to Assets/temp/hotspot/img/logohotspot.asp or any .asp file under Assets/temp/hotspot/img/.
- Monitor the FortiLogger upload directory for newly created files with executable extensions.
- Correlate upload events with subsequent process creation or outbound connections from the FortiLogger host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/161601/FortiLogger-4.4.2.2-Arbitrary-File-Upload.html | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/161974/FortiLogger-Arbitrary-File-Upload.html | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/erberkan/fortilogger_arbitrary_fileupload | ExploitThird Party Advisory |
| http://packetstormsecurity.com/files/161601/FortiLogger-4.4.2.2-Arbitrary-File-Upload.html | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/161974/FortiLogger-Arbitrary-File-Upload.html | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/erberkan/fortilogger_arbitrary_fileupload | ExploitThird Party Advisory |
Track CVE-2021-3378 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-3378), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.