logo

Massive FortiGate Config Leak: Assessing the Impact

ID: 60ab1f8f-893a-5486-85bd-f566c253e22d

STIX ID: report--60ab1f8f-893a-5486-85bd-f566c253e22d

Feed Name: Censys Blog

Threat Score
85/100

Date Published: 2025-01-17

Date Updated: 2026-04-27

Author: Ivonne Francia

...
...

A newly surfaced leak by a group calling itself Belsen released full FortiGate firewall configurations and plaintext VPN credentials for 15,469 devices (data likely assembled Oct 2022 and tied to CVE-2022-40684). Censys enrichment as of Jan 17, 2025 shows ~8,469 affected IPs still online and ~5,086 exposing FortiGate web admin interfaces; a public GitHub list of affected IPs is available. Organizations are urged to check the list, rotate credentials, monitor for unauthorized access, and apply patches (notably for CVE-2024-55591).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.