An improper access control vulnerability in Fortinet FortiWebManager 5.8.0 allows anyone that can access the admin webUI to successfully log-in regardless the provided password.
Fortinet
Exploit
CVE-2017-14189
NVD
Fortinet PSIRT Advisory