CVE-2025-24472: Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability

High severity, CVSS 8.1. Actively exploited: in CISA KEV since 2025-03-18. EPSS: 7.2% chance of exploitation in the next 30 days.

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior knowledge of upstream and downstream devices serial numbers to gain super-admin privileges on the downstream device, if the Security Fabric is enabled, via crafted CSF proxy requests.

Affected products

  • Fortinet FortiOS: from 7.0.0, before 7.0.17 (fixed in 7.0.17)
  • Fortinet FortiProxy: from 7.0.0, before 7.0.20 (fixed in 7.0.20); from 7.2.0, before 7.2.13 (fixed in 7.2.13)

Published 2025-02-11. Last modified 2026-08-05.