Fortinet says attackers are exploiting a vulnerability in FortiOS and FortiProxy , which has been patched since last month, and can be used to compromise Fortinet firewalls and corporate networks .

The vulnerability is tracked as CVE-2025-24472 and allows authentication bypass. Remote attackers can gain super-admin privileges by making specially crafted CSF proxy requests.
The security issue affects FortiOS 7.0.0 to 7.0.16, FortiProxy 7.0.0 to 7.0.19, and FortiProxy 7.2.0 to 7.2.12. Fortinet has fixed it in FortiOS 7.0.17 (and later) and FortiProxy 7.0.20/7.2.13 (and later).
See also: Microsoft Patch Tuesday February 2025: Fixes 55 vulnerabilities
Fortinet added the flaw as a new CVE-ID in a security advisory issued last month. At the time, it warned customers that cybercriminals were exploiting a zero-day vulnerability in FortiOS and FortiProxy (CVE-2024-55591), which affected the same versions of the software. However, the now-patched CVE-2024-55591 flaw could be exploited by sending malicious requests to the Node.js websocket module.
According to Fortinet, attackers can exploit both vulnerabilities to create random admin or local users on affected devices, adding them to new and existing SSL VPN user groups, modify firewall policies and other configurations, and access SSLVPN instances with rogue accounts “to gain a tunnel to the internal network.network.”
While Fortinet did not provide additional information about the campaign, cybersecurity firm Arctic Wolf published an Indicators of Compromise (IOC) report , saying that vulnerable Fortinet FortiGate firewalls have been under attack since at least mid-November.
See also: Orthanc server vulnerability compromises medical data
The Arctic Wolf Labs added that it notified Fortinet about the attacks on December 12 and the company responded five days later saying that the activity was known and already under investigation.
Fortinet advised administrators who cannot immediately deploy security updatesto protect vulnerable firewalls by disabling the HTTP/HTTPS administrative interface or restricting the IP addresses that can reach it via local-in policies.

Beyond applying patches, maintaining a robust security posture is crucial to defending against vulnerability exploits. This includes integrating multiple layers of defense, including intrusion detection and prevention systems (IDPS), network segmentation, and continuous monitoring for suspicious activity.
Additionally, investing in employee training to recognize phishing attempts and other social engineering attacks can further reduce the likelihood of systems being compromised.
See also: Apple fixes second zero-day vulnerability this year!
By prioritizing proactive defense strategies alongside rapid remediation, organizations can significantly enhance their resilience against such threats and protect their infrastructure from advanced cyber attacks.
Source: www.bleepingcomputer.com
