PT-2025-6278 · Fortinet · Fortios+1
CVE-2025-24472
·
Published
2025-01-14
·
Updated
2026-09-11
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FortiOS versions 7.0.0 through 7.0.16
FortiProxy versions 7.0.0 through 7.0.19
FortiProxy versions 7.2.0 through 7.2.12
Description
An authentication bypass issue exists in the Node.js WebSocket module and CSF proxy requests. This flaw allows a remote unauthenticated attacker to gain super-admin privileges on a downstream device by sending specially crafted HTTP requests, provided the Security Fabric is enabled and the attacker has prior knowledge of the serial numbers of the upstream and downstream devices. This issue has been exploited in real-world attacks by SuperBlack ransomware to take over firewalls, with over 23,000 devices estimated to be potentially affected worldwide. Exploitation can lead to the unauthorized creation of super-admin accounts, modification of firewall configurations, establishment of SSL VPN tunnels for internal network access, and credential harvesting.
Recommendations
Update FortiOS to version 7.0.17 or later.
Update FortiProxy versions 7.0.0 through 7.0.19 to a version containing the fix.
Update FortiProxy versions 7.2.0 through 7.2.12 to version 7.2.13 or later.
Disable the HTTP/HTTPS administrative interface.
Restrict access to administrative interfaces to trusted IP addresses via local-in policies.
Remove firewall management interfaces from public internet access.
Fix
Missing Authentication
Authentication Bypass Using an Alternate Path or Channel
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fortios
Fortiproxy