LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-24472: Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 18, 2025
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Apr 8, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-24472 to its Known Exploited Vulnerabilities catalog on Mar 18, 2025, with a federal patch deadline of Apr 8, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that allows a remote attacker to gain super-admin privileges via crafted CSF proxy requests.

CVE-2025-24472 is an authentication bypass vulnerability affecting Fortinet FortiOS and FortiProxy. A remote attacker can send crafted CSF proxy requests to obtain super-admin privileges without valid credentials.

This is significant for defenders because these products commonly sit at the network perimeter or act as security gateways. Full administrative control lets an attacker reconfigure devices, intercept traffic, or pivot deeper into the environment. The vulnerability has known ransomware use, so rapid assessment and remediation are warranted.

How it works

The weakness is CWE-288 (Authentication Bypass Using an Alternate Path or Channel). FortiOS and FortiProxy do not correctly enforce authentication on certain CSF proxy request paths. An unauthenticated remote attacker can craft requests that take advantage of this alternate path, bypassing normal login controls and elevating directly to super-admin rights.

Exact request structure, required conditions, and any prerequisites are not detailed here; confirm those mechanics and any proof-of-concept details solely against the official Fortinet advisory. No exploit code or additional technical steps should be assumed beyond the CISA description of crafted CSF proxy requests leading to super-admin access.

Am I affected? How to find it in your systems

FortiOS is the operating system on Fortinet FortiGate firewalls and related appliances; FortiProxy is Fortinet’s secure web proxy product. Both typically run as edge security devices, VPN gateways, or internal segmentation points in enterprise and service-provider networks.

How to remediate

Patch first. Apply the vendor updates for FortiOS and FortiProxy exactly as specified in the Fortinet security advisory for CVE-2025-24472. Confirm the precise fixed versions, upgrade paths, and any required reboot or configuration steps against that advisory; do not assume version numbers from secondary sources.

CISA’s required action is to apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for any cloud-hosted instances, or discontinue use of the product if mitigations are unavailable.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls focused on the authentication-bypass class and the CSF proxy attack surface.

If your data may have been exposed

Actively exploited authentication-bypass vulnerabilities, especially those with known ransomware use, frequently lead to full device compromise, credential theft, and subsequent data encryption or exfiltration. Treat any unpatched, internet-reachable instance as potentially compromised: isolate it, preserve logs, hunt for persistence, and rotate all related credentials and certificates.

As an additional check, you can run a free exposure scan of your email addresses against known breach data sets to see whether associated credentials or personal information have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedFortinet · FortiOS and FortiProxy
WeaknessCWE-288
Added to CISA KEVMar 18, 2025
Federal patch deadlineApr 8, 2025
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities