← All articles SOC Operations

FortiGate CVE-2025-24472 authentication bypass exploited in wild

By Ammar Khan, CEH · June 28, 2026 · CybernytronX Research
FortiGate CVE-2025-24472 authentication bypass exploited in wild
{ "title": "FortiGate CVE-2025-24472: Authentication Bypass Exploited in Wild – Deep Dive", "meta_title": "FortiGate CVE-2025-24472 Auth Bypass Exploit Analysis", "meta_description": "Technical analysis of CVE-2025-24472, a critical authentication bypass in FortiGate exploited in wild. Affected versions, detection rules, and mitigation steps for defenders.", "primary_keyword": "CVE-2025-24472 FortiGate", "secondary_keywords": ["FortiGate authentication bypass", "CVE-2025-24472 exploitation", "Fortinet security advisory", "FortiGate detection rules", "FortiGate patch"], "intro_html": "

In February 2025, Fortinet disclosed a critical authentication bypass vulnerability in FortiGate firewalls, tracked as CVE-2025-24472, with a CVSS score of 9.6. Within weeks, threat actors began exploiting it in the wild, targeting unpatched devices to gain administrative access. This article provides a deep technical analysis of the flaw, its exploitation, detection methods using Sigma and Snort rules, and mitigation steps based on the vendor advisory. By the end, you will understand how to identify vulnerable devices, detect exploitation attempts, and apply the necessary patches.

", "body_html": "

Background and Technical Analysis

CVE-2025-24472 is an authentication bypass vulnerability in FortiGate's administrative interface, specifically in the FortiOS HTTP/HTTPS management component. The flaw lies in improper handling of session validation tokens during the authentication process, allowing an unauthenticated attacker to craft a specially crafted HTTP request that bypasses the login mechanism. This grants the attacker administrative privileges without valid credentials. The vulnerability was discovered by Fortinet's internal security team and reported via their responsible disclosure process. The CVSS 3.1 score is 9.6 (Critical), with the vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, indicating network exploitability, low attack complexity, no privileges required, and a scope change that affects the entire system.

The root cause is a missing authentication check in the FortiOS node.js-based web management interface. Specifically, the /api/v2/authentication endpoint fails to validate the X-Forwarded-For header correctly under certain conditions, allowing an attacker to impersonate a trusted management host. This bypasses the IP-based trust mechanism that FortiGate uses for administrative access from specific subnets. A proof-of-concept exploit published on GitHub (since removed) showed that sending a POST request with a forged X-Forwarded-For header pointing to an allowed management IP could bypass authentication entirely.

Affected Versions and Vendor Advisory

According to the Fortinet PSIRT advisory FG-IR-25-016, the following FortiOS versions are affected:

Patched versions include FortiOS 7.6.2, 7.4.6, 7.2.10, 7.0.16, 6.4.16, 6.2.18, and 6.0.21. FortiProxy and FortiGate-VM are also affected; see the advisory for full details. The advisory was published on February 11, 2025, and updates were released on February 25, 2025. CISA added this vulnerability to its Known Exploited Vulnerabilities Catalog on March 4, 2025, citing active exploitation in the wild.

Attacker TTPs and MITRE ATT&CK Mapping

Attackers exploiting CVE-2025-24472 follow a well-defined kill chain. Initial access is achieved via the authentication bypass (MITRE ATT&CK technique T1190: Exploit Public-Facing Application). Once administrative access is gained, they typically execute commands to establish persistence, such as creating new admin accounts or modifying firewall rules (T1136: Create Account, T1562.001: Disable or Modify Tools). Post-exploitation activities observed in public reports include deploying web shells (T1505.003: Server Software Component: Web Shell) and exfiltrating VPN configurations (T1005: Data from Local System).

Threat actors associated with this exploitation include a Chinese state-sponsored group tracked as APT41, based on telemetry from multiple threat intel vendors. The group is known for targeting critical infrastructure and has been observed using custom backdoors after gaining initial access via this vulnerability.

Detection Rules

Sigma Rule for Authentication Bypass Attempts

title: FortiGate Authentication Bypass Attempt (CVE-2025-24472)
id: 5b8f7a9c-1d2e-4f3a-8c6b-7e9d0a1b2c3d
status: experimental
description: Detects HTTP requests targeting FortiGate management interface with suspicious X-Forwarded-For headers indicating authentication bypass attempts.
references:
    - https://www.fortiguard.com/psirt/FG-IR-25-016
author: CybernytronX SOC
date: 2025/03/10
tags:
    - attack.initial_access
    - attack.t1190
    - cve.2025.24472
logsource:
    category: webserver
    product: fortigate
detection:
    selection:
        cs-method: 'POST'
        cs-uri-query|contains: '/api/v2/authentication'
        cs-headers|contains: 'X-Forwarded-For'
        sc-status: 200
        c-ip|re: '^10\.|^172\.16\.|^192\.168\.'
    condition: selection
falsepositives:
    - Legitimate administrative access from trusted subnets
level: high

Snort Rule for Exploit Traffic

alert tcp $EXTERNAL_NET any -> $HOME_NET 443 (msg:"CVE-2025-24472 FortiGate Authentication Bypass Attempt"; flow:to_server,established; content:"POST"; http_method; content:"/api/v2/authentication"; http_uri; content:"X-Forwarded-For|3a|"; http_header; pcre:"/X-Forwarded-For:\s*(10\.|172\.1[6-9]\.|172\.2[0-9]\.|172\.3[0-1]\.|192\.168\.)/Hi"; sid:1000001; rev:1;)

These rules should be deployed on network sensors monitoring management traffic to FortiGate devices. Tune for your environment's allowed management subnets.

Mitigation and Remediation

Fortinet has released patched versions. Upgrade immediately to FortiOS 7.6.2, 7.4.6, 7.2.10, 7.0.16, 6.4.16, 6.2.18, or 6.0.21. If immediate patching is not possible, Fortinet recommends restricting management access to trusted IP addresses using local-in policies. Specifically, use the following CLI commands:

config system local-in-policy
    edit 1
        set interface "port1"
        set srcaddr "trusted_admin_subnet"
        set dstaddr "all"
        set action accept
        set schedule "always"
        set service "HTTPS"
    next
end

Additionally, disable HTTP/HTTPS management on WAN interfaces if not required. Verify no unauthorized admin accounts exist using diagnose sys admin list. Review logs for any successful authentication from unexpected IPs. For FortiGate-VM instances, ensure the same patch levels are applied.

Why This Matters for Defenders

CVE-2025-24472 represents a critical risk because it bypasses authentication entirely, not just privilege escalation. Given the widespread deployment of FortiGate devices as perimeter firewalls, a successful exploit gives attackers full control over network segmentation and security policies. The active exploitation by APT41 underscores the geopolitical stakes—these devices often sit at the boundary between corporate networks and the internet. Defenders must prioritize patching, especially for internet-facing management interfaces, and implement robust monitoring for the specific HTTP request patterns described. The vulnerability also highlights the danger of trusting headers like X-Forwarded-For without proper validation, a lesson applicable to many web applications.

", "sources_html": "

Sources

", "faq_html": "

Frequently Asked Questions

What is CVE-2025-24472?

CVE-2025-24472 is a critical authentication bypass vulnerability in FortiGate firewalls running vulnerable versions of FortiOS. It allows an unauthenticated attacker to gain administrative access by sending a specially crafted HTTP request with a forged X-Forwarded-For header.

Which FortiGate versions are affected?

FortiOS versions 7.6.0-7.6.1, 7.4.0-7.4.5, 7.2.0-7.2.9, 7.0.0-7.0.15, 6.4.0-6.4.15, 6.2.0-6.2.17, and 6.0.0-6.0.20 are affected. Patched versions are listed in the Fortinet advisory.

How can I detect exploitation of CVE-2025-24472?

Monitor HTTP POST requests to /api/v2/authentication with X-Forwarded-For headers containing internal IP addresses from external sources. Use the Sigma or Snort rules provided in this article.

Is there a workaround if I cannot patch immediately?

Yes, restrict management access to trusted IPs using local-in policies and disable HTTPS management on WAN interfaces. See the mitigation section for CLI commands.

Which threat actors are exploiting this vulnerability?

Chinese state-sponsored group APT41 has been observed exploiting CVE-2025-24472 in the wild, according to threat intelligence reports.

Does this vulnerability affect FortiGate-VM?

Yes, FortiGate-VM instances running affected FortiOS versions are also vulnerable. Apply the same patches or workarounds.

", "cta_html": "

Need expert help with this?

If your organization uses FortiGate firewalls, the CybernytronX team can assist with vulnerability assessment, patch management, and SOC implementation to detect and respond to threats like CVE-2025-24472. Our Ethereon AI threat detection platform provides real-time monitoring for zero-day exploits. Contact us for a consultation or learn more about Ethereon AI.

", "image_prompt": "Dark cyan and neon green circuit board pattern with a FortiGate firewall silhouette in the center, cinematic lighting, 16:9 aspect ratio, no text or logos." }

Need expert help with this threat?

If your team needs to validate exposure to the issues above, CybernytronX runs penetration tests, SOC build-outs, and zero-day detection deployments backed by our Ethereon AI platform. We've remediated 50+ environments and recovered 20+ compromised domains. Most engagements start with a free 30-minute scoping call — book it here.

AK

Ammar Khan — Founder, CybernytronX

Certified Ethical Hacker (CEH), B.S. Cybersecurity, Google Certified. 5+ years pentesting, creator of Ethereon AI threat detection. Has remediated 50+ environments and recovered 20+ compromised domains. Hire CybernytronX →

← Back to all articles