← Intelligence Center

Fortinet Releases Advisory on New Post-Exploitation Technique for Known Vulnerabilities

PublishedApr 11, 2025
Updated
VendorFortinet
SeverityUnspecified
Known ExploitedYes Known Exploited
Advisory IDINTEL-000027
CVEs
None identified.
Products
  • FortiOS
  • FortiGate

Executive Summary

Fortinet is aware of a threat actor creating a malicious file from previously exploited Fortinet RCE vulnerabilities within FortiOS and FortiGate products. This malicious file could enable read-only access to files on the devices' file system, which may include configurations.

Municipal Impact

Municipalities running FortiGate/FortiOS should upgrade to the indicated fixed versions and review device configurations, as exposed firewalls and SSL-VPNs are common targets.

SMB Impact

SMBs using FortiGate should upgrade to the fixed FortiOS versions, reset potentially exposed credentials, and consider disabling SSL-VPN until patched.

Recommended Actions

  1. Upgrade to FortiOS versions 7.6.2, 7.4.7, 7.2.11, 7.0.17, or 6.4.16 to remove the malicious file and prevent re-compromise.
  2. Review the configuration of all in-scope devices.
  3. Reset potentially exposed credentials.
  4. As a work-around mitigation until the patch is applied, consider disabling SSL-VPN functionality, as exploitation requires SSL-VPN to be enabled.

Grey Matter Analysis

Analysis pending review.

Need help with this advisory?

Contact Grey Matter to assess your exposure and prioritize remediation.

Contact Grey Matter