CVE-2025-24472

HIGH KEV RANSOMWARE

FortiProxy 7.0.0-7.0.19 and FortiOS 7.0.0-7.0.16 - Unauthenticated Authentication Bypass via CSF Proxy Requests

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2025-24472 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added March 18, 2025, with confirmed use in ransomware campaigns. EIP tracks 1 public exploit from researchers including razureink.

AI-analyzed exploit summary This repository provides a functional proof-of-concept exploit for CVE-2025-24472, an authentication bypass vulnerability in Fortinet FortiOS/FortiProxy. The exploit crafts malicious CSF proxy requests with manipulated headers to gain super-admin privileges without credentials.

Description

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior knowledge of upstream and downstream devices serial numbers to gain super-admin privileges on the downstream device, if the Security Fabric is enabled, via crafted CSF proxy requests.

Exploits (1)

github WORKING POC
by razureink · pythonpoc
https://github.com/razureink/cve-2025-24472-fortinet_authbypass_reproduction

This repository provides a functional proof-of-concept exploit for CVE-2025-24472, an authentication bypass vulnerability in Fortinet FortiOS/FortiProxy. The exploit crafts malicious CSF proxy requests with manipulated headers to gain super-admin privileges without credentials.

Classification
Working Poc 98%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Fortinet FortiOS 7.0.0–7.0.16, FortiProxy 7.2.0–7.2.12 / 7.0.0–7.0.19
No auth needed
Prerequisites: Target device serial number (enumeration list provided) · Security Fabric feature enabled on target
mistral-large-3 · analyzed Jul 23, 2026 Full analysis →

Scores

CVSS v3 8.1
EPSS 0.0334
EPSS Percentile 87.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2025-03-18
VulnCheck KEV 2025-02-11
ENISA EUVD EUVD-2025-3725
Ransomware Use Confirmed
CWE
CWE-288
Status published
Products (5)
Fortinet/FortiOS 7.0.0 - 7.0.16
fortinet/fortios 7.0.0 - 7.0.17
Fortinet/FortiProxy 7.0.0 - 7.0.19
fortinet/fortiproxy 7.0.0 - 7.0.20
Fortinet/FortiProxy 7.2.0 - 7.2.12
Published Feb 11, 2025
KEV Added Mar 18, 2025
Tracked Since Feb 18, 2026