• News/
  • https://www.bleepingcomputer.com/news/security/fortinet-discloses-second-firewall-auth-bypass-patched-in-january/

Fortinet discloses second firewall auth bypass patched in January

BleepingComputer
·
Sergiu Gatlan
·
Published Feb 11, 2025
·
Updated

Update 2/11/25 07:32 PM ET: After publishing our story, Fortinet has informed us that the new CVE-2025-24472 flaw added to FG-IR-24-535 today is not a zero-day and was already fixed in January. Furthermore, even though today's updated advisory indicates that both flaws were exploited in attacks and even includes a workaround for the new CSF proxy requests exploitation pathway, Fortinet says that only CVE-2024-55591 was exploited. Fortinet told BleepingComputer that if a customer previously upgraded based on the guidance in FG-IR-24-535 / CVE-2024-55591, then they are already protected against the newly disclosed vulnerability. The title of our story has been updated to reflect this new information, and our original article is below. Fortinet warned today that attackers are exploiting another now-patched zero-day bug in FortiOS and FortiProxy to hijack Fortinet firewalls and breach enterprise networks. Successful exploitation of this authentication bypass vulnerability (CVE-2025-24472) allows remote attackers to gain super-admin privileges by making maliciously crafted CSF proxy requests. The security flaw impacts FortiOS 7.0.0 through 7.0.16, FortiProxy 7.0.0 through 7.0.19, and FortiProxy 7.2.0 through 7.2.12. Fortinet fixed it in FortiOS 7.0.17 or above and FortiProxy 7.0.20/7.2.13 or above. Fortinet added the bug as a new CVE-ID to a security advisory issued last month cautioning customers that threat actors were exploiting a zero-day vulnerability in FortiOS and FortiPro...

Read full article

Affected Software

8 affected components
Fortinet FortiOS=7.0.0
Fortinet FortiOS=7.0.16
Fortinet FortiProxy=7.0.0
Fortinet FortiProxy=7.0.19
Fortinet FortiProxy=7.2.0
Fortinet FortiProxy=7.2.12
Fortinet FortiOS
Fortinet FortiProxy
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a newly disclosed vulnerability in Fortinet firewalls that was patched in January.

2

What security implications are discussed?

The vulnerability allows for an authentication bypass, potentially compromising firewall security.

3

What products or software are affected?

The affected products include Fortinet FortiOS and FortiProxy versions 7.0.0, 7.0.16, 7.0.19, and 7.2.0, 7.2.12.

4

Has this vulnerability been active since it was disclosed?

No, Fortinet clarified that the vulnerability was not a zero-day and had already been fixed in January.

5

What is the CVE associated with this vulnerability?

The vulnerability is identified as CVE-2025-24472.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203