FortiOS Vulnerability Enables Unauthorized Device Access via Authentication Bypass

FortiOS Vulnerability Enables Unauthorized Device Access via Authentication Bypass

Severe Fortinet Exploit Lets Attackers Sidestep Logins, Hijack Network Devices

A newly disclosed flaw in Fortinet’s security ecosystem poses a serious risk to network infrastructure. Identified as CVE-2025-22252, this vulnerability allows threat actors to completely bypass login mechanisms and gain full administrative privileges—no credentials required.

The bug resides in the TACACS+ implementation using ASCII authentication, and it affects several core Fortinet platforms: FortiOS, FortiProxy, and FortiSwitchManager. If configured with the vulnerable method, these systems can be infiltrated by anyone with knowledge of existing admin usernames—giving attackers unrestricted access to critical infrastructure.

Why It’s Dangerous

This flaw doesn’t just expose one device—it potentially opens the door to entire networks. Once inside, attackers can:

  • Seize full control of Fortinet-managed systems
  • Escalate privileges across connected services
  • Launch deeper network intrusions or disrupt operations
  • Steal sensitive data without triggering authentication alerts

Vulnerable Systems

The bug impacts the following versions:

  • FortiOS: 7.6.0, 7.4.4–7.4.6
  • FortiProxy: 7.6.0–7.6.1
  • FortiSwitchManager: 7.2.5

Good news: systems running FortiOS 7.2, 7.0, 6.4, and older versions of FortiProxy or FortiSwitchManager are not affected—provided they don’t use ASCII with TACACS+.

What to Do Now

Fortinet urges customers to upgrade immediately to safe versions:

  • FortiOS: 7.6.1 or later, 7.4.7 or later
  • FortiProxy: 7.6.2 or later
  • FortiSwitchManager: 7.2.6 or later

Can’t Patch Right Away?

A workaround is available: switch your authentication method. Alternatives such as PAP, MSCHAP, or CHAP do not suffer from this vulnerability. This change can be applied via the CLI by adjusting the device’s TACACS+ configuration.

Why ASCII Authentication?

Unlike other methods, ASCII authentication handles credentials in a more flexible but less secure way—making it uniquely vulnerable in this case. The flaw doesn’t impact environments that rely solely on other protocols.

Recognition and Additional Threats

Credit for uncovering the flaw goes to Cam B (Vital) and Matheus Maia (NBS Telecom), whose responsible disclosure helped Fortinet patch the issue before widespread exploitation. Additionally, Fortinet recently fixed a separate zero-day vulnerability in FortiVoice, which was already being exploited in the wild.

Final Recommendation

If your organization uses Fortinet gear with TACACS+ configured for ASCII authentication, this is not a drill. Review configurations immediately and prioritize updates or mitigation steps to defend against unauthorized access and potential system-wide compromise.

More Articles & Posts