Hackers exploit old FortiGate vulnerabilities, use symlink trick to retain limited access to patched devices
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-42475 | Unauthenticated Heap Overflow in Fortinet FortiOS/FortiProxy SSL-VPN (Critical RCE) CVE-2022-42475 is a critical (CVSS 9.8) heap-based buffer overflow in the SSL-VPN service of Fortinet FortiOS and FortiProxy. A remote, unauthenticated attacker can trigger it by sending specifically crafted requests to an exposed SSL-VPN interface, with no user interaction or credentials required. Successful exploitation yields arbitrary code or command execution on the appliance, giving attackers a foothold on the perimeter device from which they can pivot into internal networks. Any organization running the listed FortiOS (6.0 through 7.2) or FortiProxy (7.0/7.2) versions with SSL-VPN enabled is affected. Exploitation is confirmed in the wild: the flaw is in CISA KEV with known ransomware use, has near-certain exploitation probability (EPSS 99.5%), and has been used in targeted government attacks and a Chinese-nexus espionage campaign that compromised over 20,000 systems, with attackers also noted to retain access even after patching. Do: Upgrade FortiOS and FortiProxy to fixed releases per Fortinet advisory FG-IR-22-398 (any version beyond the listed affected ranges), and reboot the appliance after patching to clear lingering SSL-VPN sessions since attackers have been observed retaining access post-patch. Check for indicators of compromise such as unknown local accounts, unexpected processes, and anomalous historical logins, and rotate SSL-VPN credentials if compromise is suspected. If SSL-VPN is not required, disable it or restrict exposure to trusted sources until patched. | 9.8 | 99% | KEV ransomware PoC |
| masshundreds of thousands of internet-exposed FortiGate/FortiProxy SSL-VPN endpoints (well over 100,000; 20,000+ confirmed victims in a single campaign) | |
| CVE-2023-27997 | Pre-Auth Heap Buffer Overflow RCE in Fortinet FortiOS/FortiProxy SSL-VPN CVE-2023-27997 is a heap-based buffer overflow (CWE-122, with associated out-of-bounds write CWE-787) in the SSL-VPN component of Fortinet FortiOS and FortiProxy, reachable by unauthenticated users. A remote attacker can trigger it with specially crafted requests to the SSL-VPN web interface, gaining the ability to execute arbitrary code or commands on the gateway. Full control of an edge VPN/firewall appliance enables credential theft, session hijacking, and pivoting into the protected network, which makes the bug attractive to ransomware operators. Any organization exposing the SSL-VPN portal on the affected FortiOS builds (7.2.4 and below, 7.0.11 and below, 6.4.12 and below, 6.0.16 and below) or FortiProxy builds (7.2.3 and below, 7.0.9 and below, 2.0.12 and below, and 1.1/1.2 all versions) is potentially exposed. The flaw is under active exploitation: CISA added it to the KEV on 2023-06-13 with known ransomware use, EPSS estimates an ~86% probability of exploitation within 30 days (100th percentile), and reporting indicates it was likely being exploited in the wild, with Fortinet also warning that some attackers retained access to FortiGate devices even after patching. Do: Apply Fortinet's updates to all SSL-VPN-enabled FortiOS and FortiProxy appliances as required by the CISA KEV listing, upgrading each affected branch beyond the listed versions (end-of-life FortiProxy 1.1/1.2 requires migration to a supported release); if SSL-VPN is not needed, disable the web portal or restrict it to trusted source addresses. After patching, hunt for signs of compromise and rotate credentials and VPN-related secrets, since Fortinet warned that some attackers retained access to FortiGate devices post-patching. | 9.8 | 86% | KEV ransomware |
| masson the order of several hundred thousand internet-exposed SSL-VPN endpoints (≈300k–500k per public scans) | |
| CVE-2024-21762 | Out-of-Bounds Write RCE in Fortinet FortiOS and FortiProxy CVE-2024-21762 is a critical (CVSS 9.8) out-of-bounds write (CWE-787) in the SSL VPN functionality of Fortinet FortiOS and FortiProxy, allowing an unauthenticated remote attacker to execute unauthorized code or commands by sending specifically crafted requests to the vulnerable service. No authentication or user interaction is required, and network access to the SSL VPN interface is the only precondition. Organizations running affected FortiOS versions (on FortiGate appliances) or any affected FortiProxy version are exposed, particularly where the SSL VPN is internet-facing. The flaw is actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2024-02-09 with ransomware use noted, EPSS puts the 30-day exploitation probability at 84.3%, and public scans suggest roughly 150,000 internet-exposed Fortinet devices may be impacted. Do: Upgrade FortiOS and FortiProxy to fixed releases outside the affected ranges per Fortinet's advisory, prioritizing internet-facing devices; as an interim mitigation, disable SSL VPN (or SSL VPN web mode) where it is not required, per vendor and CISA guidance. After patching, check for signs of compromise and rotate credentials, since Fortinet has warned that attackers retained access to FortiGate devices post-patching. The flaw is in CISA KEV with known ransomware use, so treat this as an urgent patching priority. | 9.8 | 84% | KEV ransomware |
| mass≈150,000 internet-exposed FortiGate/FortiProxy devices (public internet-wide scans) |
Full article619 words · extracted from helpnetsecurity.com · click to collapse
A threat actor that has been using known old FortiOS vulnerabilities to breach FortiGate devices for years has also been leveraging a clever trick to maintain undetected read-only access to them after the original access vector was locked down, Fortinet has revealed on Thursday.

“[Read-only access] was achieved via creating a symbolic link connecting the user filesystem and the root filesystem in a folder used to serve language files for the SSL-VPN,” Fortinet CISO Carl Windsor explained.
“This modification took place in the user filesystem and avoided detection. Therefore, even if the customer device was updated with FortiOS versions that addressed the original vulnerabilities, this symbolic link may have been left behind, allowing the threat actor to maintain read-only access to files on the device’s file system, which may include configurations.”
He did not say when Fortinet first detected the use of this post-exploitation technique, nor did he share for how long they believe the threat actor had been using the technique.
Fortinet warns
The threat actor has been and is exploiting CVE-2022-42475, CVE-2023-27997 and CVE-2024-21762 to achieve remote code execution.
Windsor said that in FortiOS versions 7.6.2, 7.4.7, 7.2.11, 7.0.17, and 6.4.16, the the malicious symbolic link is automatically removed and the SSL-VPN user interface is prevented from serving such malicious symbolic links.
Even before that, the company released FortiOS versions 7.4, 7.2, 7.0, and 6.4, with an AV/IPS signature to detect and clean the symbolic link from impacted devices, though this worked only if “the [IPS] engine was licensed and enabled.”
Earlier this week, Fortinet started sending out an email notice to an unknown number of customers, saying that their telemetry shows they had been affected and advising them to take immediate action by:
- Upgrading to FortiOS versions 7.6.2, 7.4.7, 7.2.11, 7.0.17 or 6.4.16 to remove the malicious file and prevent a new compromise
- Reviewing the configuration of the device but also treating it as potentially compromised
- Going through the steps outlined here, which include resetting all users’ credentials, revoking certificates, resetting secrets, etc.
CERTs advise
The German Federal Office for Information Security (BSI) has issued a security notice advising organizations using Fortinet’s firewalls to check whether they have been or are affected and take further protective measures.
“In this context, they should particularly check whether any unsuccessful attempts to contact the manufacturer via the established communication channels with Fortinet have been made in recent weeks,” the BSI said.
“If a compromise is detected, extensive forensic analysis of the device itself and investigations of other network components for suspicious activity should be conducted before the reset to rule out a deeper compromise of the network. For environments with increased security requirements, the BSI recommends, in addition to installing patches, also evaluating the preventive exchange of relevant access credentials … to counteract the risk of a possible leak of configuration and access data.”
The BSI finally pointed out that, in Germany, as of April 10, 2025, there are still almost 700 FortiGate devices vulnerable to CVE-2024-21762.
The French Computer Emergency Response Team (CERT-FR) said that it is aware of a massive campaign involving numerous devices in France compromised through the aforementioned vulnerabilities. “During incident response operations, CERT-FR became aware of compromises that occurred since early 2023,” they said, and advised on how to perform a full investigation into whether the attacker got beyond the firewall.
In early 2025, a threat actor leaked configuration files containing admin and VPN user credentials for over 15,000 Fortinet Fortigate firewalls. It is believed that the threat actor extracted those files after exploiting a FortiOS authentication bypass vulnerability (CVE-2022–40684).

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/04/11/fortios-fortigate-vulnerabilities-symlink-trick-limited-access/