An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.
Published: 2025-01-14
Fortinet patched a zero day authentication bypass vulnerability in FortiOS and FortiProxy that has been actively exploited in the wild as a zero-day since November 2024.
https://www.securityweek.com/ivanti-fortinet-patch-remote-code-execution-vulnerabilities/
https://thehackernews.com/2025/02/ivanti-patches-critical-flaws-in.html
https://www.theregister.com/2025/01/21/fortinet_firewalls_still_vulnerable/
https://www.securityweek.com/fortinet-confirms-new-zero-day-exploitation/