HomeSecurityFortinet FortiWeb: Exploit released for critical vulnerability

Fortinet FortiWeb: Exploit released for critical vulnerability

A serious vulnerability affecting Fortinet FortiWeb has been exploited in recent days by cybercriminals, who create illegitimate administrator accounts without requiring any form of authentication. This weakness has raised alarm among organizations and security experts worldwide, as it allows full access to critical network infrastructure.

FortiWeb Fortinet

Fortinet has already integrated a fix into FortiWeb 8.0.2, urging administrators to immediately update their systems and check for possible unauthorized access.

First detections: A vulnerability already in use

Threat analysis firm Defused detected the first recorded exploit activity on October 6, when it observed an unknown exploit being used to create new administrator accounts on devices FortiWeb exposed

See also: CISA: Warns federal agencies about Cisco vulnerabilities

The attacks came from a wide range of IP addresses, including:

  • 107.152.41.19
  • 144.31.1.63
  • Addresses within the range 185.192.70.0/24
  • 64.95.13.8

The variety of sources indicates that the exploit is now widely distributed, perhaps through automated scanning tools.

Confirmation from watchTowr Labs: Connection attempt – exploit – access

Security analysts at watchTowr Labs published a video demonstrating the problem: a failed login attempt to FortiWeb is followed by the execution of the exploit, which in turn allows successful login as a new administrator.

Additionally, the team released a tool called “FortiWeb Authentication Bypass Artifact Generator”which can help organizations and analysts identify whether a system is exposed.

Which versions are affected – Where is the vulnerability located?

According to Rapid7, the issue is found in FortiWeb versions 8.0.1 and earlier, with version 8.0.2 resolving the issue. Despite the severity of the vulnerability, there is still no report on Fortinet's PSIRT site, raising questions about the official notification process.

See also: Vulnerability in Dell Data Lakehouse allows privilege escalation

Fortinet FortiWeb: Exploit released for critical vulnerability

The vulnerability is related to an incorrect path that allows attackers to execute requests to the following endpoint:

/api/v2.0/cmdb/system/admin%3f/../../../../../cgi-bin/fwbcgi

Through POST requests, attackers can create new accounts administrator, completely bypassing the authentication mechanism.

How attackers operate – Examples of malicious accounts

According to the findings of Daniel Card (PwnDefend / Defused), attackers create multiple accounts with usernames such as:

  • Testpoint
  • trader1
  • trader

The passwords that have been identified are equally characteristic:

  • 3eMIXX43
  • AFT3$tH4ck
  • AFT3$tH4ckmet0d4yaga!n

Creating multiple admin accounts suggests an automated process and an attempt to maintain access even if an account is discovered and removed.

The situation is escalating: Global spread of attacks

Since the initial reports in early October, the attacks have not only continued but have expanded internationally. Many organizations that expose FortiWeb appliances directly to the internet are reporting suspicious activity.

The absence of official documentation from Fortinet is adding to the climate of concern, with several experts calling for a more transparent notification process.

See also: CISA: WatchGuard Fireware flaw exposes 54,000 Fireboxes

Fortinet FortiWeb: Exploit released for critical vulnerability

What administrators should do immediately

Given the seriousness of the situation, experts recommend specific steps:

1. Immediate update to FortiWeb 8.0.2 or later

It is the only confirmed fix for now.

2. Check for unrecognized admin accounts

Especially those that have been created recently.

3. Review logs for requests to the “fwbcgi”

Any activity there is an indication of an attack.

4. Access restriction

Management interfaces should only via VPN or from trusted networks. Direct exposure to the internet is a high risk.

Another reminder of the importance of patching

This incident highlights once again how vulnerable network devices can be when left unpatched. With attackers already exploiting the security gap, administrators must act quickly and decisively – before the vulnerability leads to serious breaches of infrastructure and data.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS