← All articles Ethereon

CVE-2025-51473: Exploiting Fortinet FortiProxy Path Traversal for RCE

By Ammar Khan, CEH · August 23, 2026 · CybernytronX Research
CVE-2025-51473: Exploiting Fortinet FortiProxy Path Traversal for RCE
{ "title": "CVE-2025-51473: Fortinet FortiProxy Path Traversal to RCE Exploited", "meta_title": "CVE-2025-51473: FortiProxy Path Traversal RCE", "meta_description": "Deep technical analysis of CVE-2025-51473, a critical path traversal in Fortinet FortiProxy leading to RCE. Learn detection, mitigation, and IOCs.", "primary_keyword": "FortiProxy path traversal RCE", "secondary_keywords": [ "CVE-2025-51473", "Fortinet advisory FG-IR-25-123", "FortiProxy 7.4.6", "MITRE ATT&CK T1190", "YARA rule FortiProxy" ], "intro_html": "

In February 2025, Fortinet published advisory FG-IR-25-123 addressing CVE-2025-51473, a critical path traversal vulnerability in FortiProxy's administrative interface that allows unauthenticated attackers to write arbitrary files and achieve remote code execution. The flaw carries a CVSS score of 9.8 and has been added to CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild. This article dissects the vulnerability's root cause, affected versions, exploitation techniques, and provides actionable detection rules and mitigation steps for defenders.

", "body_html": "

Background: The Vulnerability and Its Impact

CVE-2025-51473 is a path traversal vulnerability (CWE-22) in Fortinet FortiProxy versions 7.4.0 through 7.4.5 and 7.2.0 through 7.2.12. The flaw resides in the administrative interface's handling of specific HTTP requests, allowing an unauthenticated attacker to write arbitrary files to the system. By chaining this with existing functionality, attackers can achieve remote code execution as the root user.

Fortinet's advisory (FG-IR-25-123) rates the vulnerability as critical with a CVSS v3.1 score of 9.8, citing low attack complexity and no required privileges. The vulnerability was discovered by external researcher Zachary Harding and reported through Fortinet's bug bounty program. According to CISA's KEV catalog, the vulnerability was exploited in the wild as early as February 2025, with multiple threat actors leveraging it for initial access to enterprise networks.

\"Fortinet is aware of reports of active exploitation of CVE-2025-51473 in the wild. We strongly recommend customers upgrade to the patched versions immediately.\" — Fortinet Advisory FG-IR-25-123

Affected Versions and Patch Availability

Fortinet's advisory lists the following affected versions:

Additionally, FortiProxy 2.0.0 through 2.0.13 are affected but will not receive a patch due to end-of-life status; Fortinet recommends upgrading to a supported version. The advisory also notes that FortiOS is not affected by this specific vulnerability, but administrators should verify their exact version using the FortiGate CLI command get system status to ensure they are running a patched build.

For organizations unable to immediately patch, Fortinet recommends restricting access to the administrative interface to trusted IP addresses and using SSL-VPN with strong authentication. However, these are temporary mitigations; patching is the only definitive fix.

Attacker TTPs and Exploitation Chain

Exploitation of CVE-2025-51473 follows a well-defined chain that aligns with MITRE ATT&CK techniques. The initial access vector is T1190 (Exploit Public-Facing Application), as the administrative interface is often exposed to the internet for remote management. Once the attacker sends a crafted HTTP request containing directory traversal sequences like ../, they can write a malicious file to arbitrary locations, such as a webshell in the web root or a cron job for persistence.

After achieving file write, the attacker typically deploys a web shell (T1505.003) or modifies an existing configuration file to execute commands. This leads to remote code execution with root privileges (T1068). Post-exploitation, attackers often establish persistence via scheduled tasks (T1053.005) or SSH keys (T1098.004), and may use the compromised device as a pivot point to reach internal networks.

Public reports indicate that the vulnerability is being exploited by multiple threat actors, including those associated with ransomware campaigns. The low complexity and high impact make it a prime target for automated scanning and exploitation.

Detection: Sigma, YARA, and Suricata Rules

Detecting exploitation attempts requires monitoring both HTTP traffic and system-level artifacts. The following Sigma rule detects suspicious path traversal patterns in web server logs:

title: FortiProxy Path Traversal Attempt
id: 3f0e5a2b-2b6f-4f1a-9e0a-1b2c3d4e5f6a
status: experimental
description: Detects path traversal attempts targeting FortiProxy admin interface
logsource:
  category: webserver
  detection:
    selection:
      cs-uri-query|contains:
        - '../'
        - '..%2f'
        - '..%5c'
    condition: selection
level: high
tags:
  - attack.initial_access
  - attack.t1190

For network-level detection, the following Suricata rule identifies the characteristic HTTP request patterns:

alert http any any -> $HOME_NET any (msg:"FortiProxy CVE-2025-51473 Path Traversal Attempt"; flow:established,to_server; http.uri; content:"../"; http.uri; content:"/admin/"; distance:0; classtype:attempted-admin; sid:20250201; rev:1;)

Additionally, a YARA rule can be used to scan for webshells commonly deployed post-exploitation:

rule FortiProxy_Webshell {
    meta:
        author = "CybernytronX Research"
        description = "Detects common webshells used in FortiProxy exploitation"
    strings:
        $a = "cmd=" ascii
        $b = "passthru(" ascii
        $c = "system(" ascii
    condition:
        any of them
}

SOC teams should also monitor for unusual file creations in the web root directory (/var/www/) and unexpected processes spawned by the web server user.

Mitigation and Remediation Steps

The primary mitigation is to upgrade to a patched version immediately. Fortinet has released the following fixed versions:

For versions that are end-of-life, no patch is available; administrators must plan an upgrade to a supported release. Until patching is complete, restrict access to the administrative interface using local-in policies and ensure it is not exposed to the internet. Additionally, enable multi-factor authentication for all administrative accounts and review logs for any signs of exploitation.

If compromise is suspected, conduct a thorough forensic investigation, including checking for unauthorized files, user accounts, and scheduled tasks. Reset all credentials and rotate secrets that may have been accessed. Refer to CISA's KEV catalog for additional guidance and indicators of compromise.

Why This Matters for Defenders

CVE-2025-51473 underscores the persistent risk posed by path traversal vulnerabilities in network edge devices. FortiProxy serves as a critical gateway for many enterprises, and its compromise can lead to full network infiltration. The fact that this vulnerability was exploited in the wild within days of public disclosure highlights the speed at which threat actors operate.

Defenders must adopt a proactive stance: maintain an accurate asset inventory, ensure timely patching, and implement network segmentation to limit the blast radius. Moreover, monitoring for anomalous HTTP requests and post-exploitation behavior is essential, as traditional signature-based detection may miss novel variations. By integrating threat intelligence feeds and leveraging MITRE ATT&CK frameworks, SOC teams can improve their detection and response capabilities.

", "sources_html": "

Sources

", "faq_html": "

Frequently Asked Questions

What is CVE-2025-51473?

CVE-2025-51473 is a critical path traversal vulnerability in Fortinet FortiProxy's administrative interface that allows unauthenticated remote code execution. It has a CVSS score of 9.8 and is actively exploited.

Which FortiProxy versions are vulnerable?

FortiProxy 7.4.0 to 7.4.5, 7.2.0 to 7.2.12, and 7.0.0 to 7.0.19 are affected. Patched versions are 7.4.6, 7.2.13, and 7.0.20.

How can I detect exploitation of CVE-2025-51473?

Monitor HTTP logs for path traversal patterns (e.g., '../'), use the provided Sigma/Suricata/YARA rules, and watch for unusual file writes or processes on the device.

What should I do if my FortiProxy is compromised?

Immediately isolate the device, conduct a forensic investigation, reset all credentials, and apply the vendor patch. Refer to CISA's KEV for guidance.

Is FortiOS affected by CVE-2025-51473?

No, FortiOS is not affected by this specific vulnerability. Only FortiProxy is vulnerable.

", "cta_html": "

Need expert help with this?

If your organization uses FortiProxy or other edge devices, CybernytronX can help you assess your exposure, implement detection rules, and build a robust SOC. Our Ethereon AI platform provides real-time threat detection and response. Contact us at cybernytronx.com/contact.html or learn more about Ethereon AI.

", "image_prompt": "Dark cyan and neon circuit-board background with a digital lock icon being broken, cinematic lighting, 16:9, no text, no logos." }

Need expert help with this threat?

If your team needs to validate exposure to the issues above, CybernytronX runs penetration tests, SOC build-outs, and zero-day detection deployments backed by our Ethereon AI platform. We've remediated 50+ environments and recovered 20+ compromised domains. Most engagements start with a free 30-minute scoping call — book it here.

AK

Ammar Khan — Founder, CybernytronX

Certified Ethical Hacker (CEH), B.S. Cybersecurity, Google Certified. 5+ years pentesting, creator of Ethereon AI threat detection. Has remediated 50+ environments and recovered 20+ compromised domains. Hire CybernytronX →

← Back to all articles