Hackers Exploit FortiGate SSL-VPN Vulnerability to Attack Broadband Provider
Exposed attacker staging server reveals intrusion of Thai broadband provider 3BB via actively exploited FortiGate SSL-VPN flaw CVE-2024-21762.
Hunt.io found an open directory on server 92.63.180[.]133 holding 298 files detailing an intrusion into Triple T Broadband's 3BB brand, starting from a FortiGate 60F SSL-VPN at mail.3bb.co[.]th:10443. The actor weaponized CVE-2024-21762 (CVSS 9.8, KEV-listed since February 2024) using heap spraying and a ROP chain to gain a reverse shell. Post-exploitation included MeshCentral root-level persistence via www.ayuthayatech[.]com, Dirty COW/PwnKit privilege escalation, credential harvesting, SSH spraying against 55+ internal addresses, and log-deleting cleanup scripts; a stolen OpenVPN certificate and key from Triple T's PKI may still be valid.
- CVE-2024-21762 (CVSS 9.8, KEV-listed) exploited via heap spray and ROP reverse shell
- MeshCentral agent installed for persistent root-level access and preserved during cleanup
- Credential theft covered SSH keys, database passwords, SNMP strings, and RADIUS databases
- Internal execution confirmed at 10.11.152.63 inside the 3BB network
- Stolen Triple T Broadband OpenVPN certificate and private key require revocation
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-21762 | Out-of-Bounds Write RCE in Fortinet FortiOS and FortiProxy CVE-2024-21762 is a critical (CVSS 9.8) out-of-bounds write (CWE-787) in the SSL VPN functionality of Fortinet FortiOS and FortiProxy, allowing an unauthenticated remote attacker to execute unauthorized code or commands by sending specifically crafted requests to the vulnerable service. No authentication or user interaction is required, and network access to the SSL VPN interface is the only precondition. Organizations running affected FortiOS versions (on FortiGate appliances) or any affected FortiProxy version are exposed, particularly where the SSL VPN is internet-facing. The flaw is actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2024-02-09 with ransomware use noted, EPSS puts the 30-day exploitation probability at 84.3%, and public scans suggest roughly 150,000 internet-exposed Fortinet devices may be impacted. Do: Upgrade FortiOS and FortiProxy to fixed releases outside the affected ranges per Fortinet's advisory, prioritizing internet-facing devices; as an interim mitigation, disable SSL VPN (or SSL VPN web mode) where it is not required, per vendor and CISA guidance. After patching, check for signs of compromise and rotate credentials, since Fortinet has warned that attackers retained access to FortiGate devices post-patching. The flaw is in CISA KEV with known ransomware use, so treat this as an urgent patching priority. | 9.8 | 84% | KEV ransomware |
| mass≈150,000 internet-exposed FortiGate/FortiProxy devices (public internet-wide scans) |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | ayuthayatech.com | s to a device group named TH-3BB and directed agents to www.ayuthayatech[.]com over port 443. A devices.json export listed multiple enro |
| domain | co.th | a FortiGate 60F SSL-VPN appliance exposed through mail.3bb.co[.]th:10443. Eight reconnaissance scripts fingerprinted the VPN |
| domain | hunt.io | configuration. Attack server file directory (Image Source: Hunt.io) Multiple artifacts referenced 3BB infrastructure directly, |
| domain | triplet.co | , including internal 10.11.x.x addresses, systems under the triplet.co.th domain, and organization-specific credentials. A capture |
Full article876 words · extracted from cybersecuritynews.com · click to collapse
Researchers have uncovered an exposed attacker-controlled staging server containing evidence of a wide-ranging intrusion targeting 3BB, the consumer brand operated by Thailand’s Triple T Broadband.
The investigation links the operation to the exploitation of a critical SSL-VPN vulnerability, followed by privilege escalation, credential theft, internal reconnaissance, lateral movement, and persistent remote access.
FortiGate SSL-VPN Vulnerability
Hunt.io first recorded the open directory at 92.63.180[.]133:8888 on June 3, 2026. Hosted on Bangmod Enterprise infrastructure, the server held 298 files in 30 subdirectories, totaling 19 MB.
The collection provided an unusually detailed view of the attacker’s operation. It included FortiGate exploitation scripts, Linux privilege-escalation tools, SSH brute-force utilities, database credential harvesters, VPN configuration files, captured session cookies, cleanup scripts, and a live MeshCentral agent configuration.

Multiple artifacts referenced 3BB infrastructure directly, including internal 10.11.x.x addresses, systems under the triplet.co.th domain, and organization-specific credentials.
A captured network configuration placed one compromised machine at 10.11.152[.]63, indicating that at least some tools were executed from inside the broadband provider’s network rather than solely from the external staging server.
The apparent initial target was a FortiGate 60F SSL-VPN appliance exposed through mail.3bb.co[.]th:10443. Eight reconnaissance scripts fingerprinted the VPN service, examined HTTP headers and FortiGate resources, and tested several historical vulnerabilities before the actor focused on CVE-2024-21762.
CVE-2024-21762 is a critical out-of-bounds write vulnerability in the FortiOS and FortiProxy SSL-VPN component. It can allow an unauthenticated remote attacker to execute arbitrary code or commands by sending specially crafted HTTP requests and carries a CVSS score of 9.8 in the NVD.
CISA added the flaw to its Known Exploited Vulnerabilities catalog in February 2024 after confirming active exploitation.
According to the recovered scripts, the attacker first used controlled crashes and malformed chunked HTTP requests to determine whether the appliance was vulnerable.
The final exploit reportedly combined heap spraying with a return-oriented programming chain to launch a reverse shell connecting to 92.63.180[.]133:9443, the same server hosting the exposed toolkit.
The actor also attempted to obtain FortiOS 7.2.5 firmware for the FortiGate 60F, apparently to identify model- and version-specific ROP gadgets. One script embedded the appliance’s serial number in a request intended to impersonate the device when contacting Fortinet’s distribution infrastructure.
After establishing access, the attacker deployed MeshCentral as a persistent remote-management backdoor. MeshCentral is a legitimate open-source platform providing remote desktop, terminal, and file-management capabilities through installed endpoint agents.
The recovered meshagent.msh configuration assigned infected machines to a device group named TH-3BB and directed agents to www.ayuthayatech[.]com over port 443.
A devices.json export listed multiple enrolled systems as connected, with several agents running as root, indicating active administrative control at the time of export.

Persistence scripts automated MeshCentral installation, checked outbound connectivity, and looked for endpoint security products before deployment.
Significantly, the attacker’s cleanup_target.sh script deleted exploitation files, web shells, authentication logs, system logs, and shell histories while intentionally preserving the MeshCentral service.
The operation extended beyond the FortiGate appliance. Eleven reconnaissance scripts targeted agent.3bb.co[.]th, a CodeIgniter-based sales portal located behind an F5 BIG-IP appliance, testing authentication, session forgery, file uploads, SQL injection, path traversal, server-side request forgery, and HTTP request smuggling.
The attacker prepared several privilege-escalation options for compromised Linux servers, including Dirty COW and PwnKit exploits, together with code for installing a concealed SUID backdoor.
Another tool targeted an internal Pentaho server using the Ghostcat vulnerability, while a captured output file reportedly documented root-level command execution on a Linux application server.
Credential-harvesting scripts searched systems for SSH private keys, PHP configuration files, database passwords, SNMP community strings, and command histories.
Other scripts targeted the radius_corp, radiusinfo, and job_radius databases, potentially exposing subscriber authentication records and network access server information.
More than 55 internal addresses were included in SSH password-spraying scripts containing both common passwords and organization-specific combinations.
The presence of 3BB-related credentials suggests prior knowledge of the environment, although the available evidence does not establish how the attacker obtained that information.
Researchers also found jasmine.ovpn, an OpenVPN profile containing a certificate and private key issued under Triple T Broadband’s public key infrastructure.
If the credential remained valid, it could potentially provide access to infrastructure associated with the Jasmine network, highlighting the importance of revoking exposed certificates rather than relying only on password resets.
Fortinet identifies FortiOS 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, and several other releases as vulnerable. Administrators should upgrade to a supported fixed release; where immediate patching is impossible, Fortinet recommends disabling SSL-VPN entirely because disabling web mode alone is not a valid workaround.
Potentially affected organizations should investigate unexpected MeshCentral agents, connections to www.ayuthayatech[.]com, reverse-shell traffic involving 92.63.180[.]133, hidden SUID files, web shells, modified SSH authorization files, and unexplained gaps in security logs.
VPN certificates, RADIUS secrets, database credentials, SSH keys, application secrets, and privileged passwords should be rotated, while forensic evidence should be preserved before remediation because the recovered toolkit shows deliberate anti-forensic activity.
Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/fortigate-ssl-vpn-vulnerability/