Actively Exploited Fortinet Zero-Day Gives Attackers Super-Admin Privileges
ID: 36c9145e-589e-58cb-8747-93ded9f731a4
STIX ID: report--36c9145e-589e-58cb-8747-93ded9f731a4
Feed Name: Dark Reading
Date Published: 2025-01-28
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Fortinet released a patch for CVE-2024-55591, a critical (CVSS 9.6) authentication-bypass in FortiOS/FortiProxy's jsconsole WebSocket that has been actively exploited to create admin accounts, modify device configurations, and use SSL VPN to access internal networks; researchers detailed a four-step exploit chain (pre-auth WebSocket, local_access_token session bypass, WebSocket Telnet race condition, and privilege selection) and Fortinet recommends following its upgrade path or applying provided workarounds and using non-guessable admin usernames.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
