Over 16,000 internet-exposed Fortinet devices have been detected as compromised with a new symlink backdoor that allows read-only access to sensitive files on previously compromised devices. This exposure is being reported by threat monitoring platform The Shadowserver Foundation, which initially reported 14,000 devices were exposed. Today, Shadowserver's Piotr Kijewski told BleepingComputer that the cybersecurity organization now detects 16,620 devices impacted by the recently revealed persistence mechanism. Last week, Fortinet warned customers that they had discovered a new persistence mechanism used by a threat actor to retain read-only remote access to files in the root filesystem of previously compromised but now patched FortiGate devices. Fortinet said that this was not through the exploitation of new vulnerabilities but is instead linked to attacks starting in 2023 and continuing into 2024, where a threat actor utilized zero days to compromise FortiOS devices. Once they gained access to the devices, they created symbolic links in the language files folder to the root file system on devices with SSL-VPN enabled. As the language files are publicly accessible on FortiGate devices with SSL-VPN enabled, the threat actor could browse to that folder and gain persistent read access to the root file system, even after the initial vulnerabilities were patched. "A threat actor used a known vulnerability to implement read-only access to vulnerable FortiGate devices. This was achi...
Over 16,000 Fortinet devices compromised with symlink backdoor
BleepingComputer
·Lawrence Abrams
·Published Apr 16, 2025
·Updated
Affected Software
4 affected components
Fortinet FortiGate
Fortinet FortiOS
Fortinet FortiOS
Fortinet FortiGate
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the compromise of over 16,000 Fortinet devices using a symlink backdoor.
2
What security implications are discussed in the article?
The symlink backdoor allows attackers to gain read-only access to sensitive files on compromised devices.
3
What types of devices are involved in this security breach?
The affected devices include Fortinet's FortiGate firewalls and FortiOS operating system.
4
How many Fortinet devices are reported to be compromised?
The article reports that more than 16,000 Fortinet devices have been compromised.
5
What is the method of attack mentioned in the article?
The attack utilizes a symlink backdoor to exploit the compromised Fortinet devices.