• News/
  • https://www.darkreading.com/endpoint-security/15k-fortinet-device-configs-leaked-dark-web

15K Fortinet Device Configs Leaked to the Dark Web

Dark Reading
·
Nate Nelson
·
Published Jan 17, 2025
·
Updated

Dated configuration data and virtual private network (VPN) credentials for 15,474 Fortinet devices have been posted for free to the Dark Web. On Jan. 14, Fortinet disclosed a severe authentication bypass vulnerability in its FortiOS operating system and FortiProxy Web gateway, CVE-2024-55591. For a model of what the aftermath of such a vulnerability could look like, one need only look to a parallel bug from October 2022 that's still making waves today. Back then, Fortinet published an urgent security warning regarding CVE-2022-40684, an equivalent authentication bypass vulnerability affecting FortiOS, FortiProxy, and the autological FortiSwitchManager. Earning a "critical" 9.8 rating in the Common Vulnerability Scoring System (CVSS), it allowed any unauthenticated attacker to perform administrative operations on vulnerable devices via specially crafted HTTP requests. In the wake of that disclosure, security researchers developed a proof-of-concept (PoC) exploit, a template for scanning for vulnerable devices, and watched as exploitation attempts climbed and climbed. On the same day CVE-2024-55591 was disclosed this week, a threat actor with the nom de guerre "Belsen Group" released data belonging to more than 15,000 Fortinet devices. In a blog post, the CloudSEK researchers who spotted it assessed that the data had been stolen thanks to CVE-2022-40684, likely when that bug was still a zero-day. Now, they wrote, "Once they exhausted its use for themselves (either by selling or...

Read full article

Affected Software

6 affected components
Fortinet FortiOS
Fortinet FortiProxy
Fortinet FortiSwitchManager
Fortinet FortiOS
Fortinet FortiProxy
Fortinet FortiSwitchManager
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the leak of configuration data and VPN credentials for over 15,000 Fortinet devices to the Dark Web.

2

What security implications are discussed in the article?

The leak raises serious concerns about the exposure and potential exploitation of vulnerable Fortinet devices due to an authentication bypass vulnerability.

3

What products or software are affected by the leak?

The affected products include Fortinet FortiOS, FortiProxy, and FortiSwitchManager.

4

When was the vulnerability in Fortinet disclosed?

Fortinet disclosed the severe authentication bypass vulnerability in its FortiOS operating system on January 14.

5

How many devices' configurations were leaked to the Dark Web?

A total of 15,474 Fortinet device configurations were leaked to the Dark Web.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203