FNT Command 13.4.0 Directory Traversal Exploit

HIGH (8.3) No Patch

Threat Intelligence

Low Risk
🔍 Detection Tools: None available in major open-source tools
⚔️ Exploit Availability: No public exploits found

How we test →

What is it?

FNT Command is a command-line utility used for file management and automation tasks. This vulnerability allows attackers to traverse directories on the target system by manipulating the FNT Command input, potentially leading to unauthorized access or data exfiltration.

Am I affected?

You're affected if you use FNT Command version 13.4.0 or earlier. To check if you're running this software, run the command fnt --version and look for the version number. If you don't recognize the name "FNT Command", you're probably not affected.

Affected Products

FNT GmbH / FNT Command

How to fix

To fix this vulnerability, upgrade to FNT Command 13.5.0 or later. You can download the patched version from the official website: https://fnt.com/download/. Immediate mitigations include:

  • Restricting access to the fnt command through a secure shell or firewall configuration.
  • Monitoring system logs for suspicious activity related to the fnt command.