PT-2025-6278 · Fortinet · Fortios+1

CVE-2025-24472

·

Published

2025-01-14

·

Updated

2026-09-11

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FortiOS versions 7.0.0 through 7.0.16 FortiProxy versions 7.0.0 through 7.0.19 FortiProxy versions 7.2.0 through 7.2.12
Description An authentication bypass issue exists in the Node.js WebSocket module and CSF proxy requests. This flaw allows a remote unauthenticated attacker to gain super-admin privileges on a downstream device by sending specially crafted HTTP requests, provided the Security Fabric is enabled and the attacker has prior knowledge of the serial numbers of the upstream and downstream devices. This issue has been exploited in real-world attacks by SuperBlack ransomware to take over firewalls, with over 23,000 devices estimated to be potentially affected worldwide. Exploitation can lead to the unauthorized creation of super-admin accounts, modification of firewall configurations, establishment of SSL VPN tunnels for internal network access, and credential harvesting.
Recommendations Update FortiOS to version 7.0.17 or later. Update FortiProxy versions 7.0.0 through 7.0.19 to a version containing the fix. Update FortiProxy versions 7.2.0 through 7.2.12 to version 7.2.13 or later. Disable the HTTP/HTTPS administrative interface. Restrict access to administrative interfaces to trusted IP addresses via local-in policies. Remove firewall management interfaces from public internet access.

Fix

Missing Authentication

Authentication Bypass Using an Alternate Path or Channel

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-01474
CVE-2025-24472

Affected Products

Fortios
Fortiproxy