Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4996 articles · 189019 vulns · 37/41 feeds (7d)
← Back to list
8.1
CVE-2025-24472KEVEXPLOITEDPATCHED
fortinet · fortiproxy

CVE-2025-24472: An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.

Description

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior knowledge of upstream and downstream devices serial numbers to gain super-admin privileges on the downstream device, if the Security Fabric is enabled, via crafted CSF proxy requests.

Affected Products

VendorProductVersions
fortinetfortiproxy7.0.0, 7.2.0, 7.0.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
fortinetfortioscve_cpe95%

References

  • https://fortiguard.fortinet.com/psirt/FG-IR-24-535

Related News (4 articles)

Tier D
Infosecurity Magazine7h ago
Gunra Ransomware Exploits Fortinet Flaws to Target Critical Infrastructure
→ No new info (linked only)
Tier D
BleepingComputer1d ago
US and South Korea warn of Gunra ransomware targeting govt agencies
→ No new info (linked only)
Tier D
The Hacker News1d ago
Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks
→ No new info (linked only)
Tier D
The Record2d ago
FBI, South Korea warn of Gunra ransomware gang targeting critical infrastructure
→ No new info (linked only)
CVSS 3.18.1 HIGH
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H/RL:O/RC:C
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
7.0.207.2.137.0.17
CWECWE-288
PublishedFeb 11, 2025
Last enriched133d ago
Trending Score131🔥
Source articles4
Independent4
Info Completeness11/14
Missing: epss, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-26035
CVE-2026-26035: An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.
Trending: 52
MEDIUMCVE-2026-70466
CVE-2026-70466: A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.
Trending: 48
MEDIUMCVE-2026-71408
CVE-2026-71408: A allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.
Trending: 43
HIGHCVE-2026-70465
CVE-2026-70465: A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiClientWindows 7.
Trending: 42
HIGHCVE-2026-70468
CVE-2026-70468: A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.
Trending: 42

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Vulnerability Timeline

CVE Published
Feb 11, 2025
Added to CISA KEV
Feb 11, 2025
Discovered by ZDM
Apr 1, 2026
Actively Exploited
Aug 5, 2026
Exploit Available
Aug 5, 2026
Patch Available
Aug 5, 2026