Configuration files for 15,000 Fortinet firewalls leaked. Are yours among them?
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2018-13379 | Unauthenticated Path Traversal in Fortinet FortiOS SSL VPN CVE-2018-13379 is a path traversal flaw (CWE-22) in the Fortinet FortiOS SSL VPN web portal that allows an unauthenticated attacker to download FortiOS system files via specially crafted HTTP resource requests. By traversing directories through crafted requests to the exposed web portal, the attacker can retrieve sensitive files, a technique publicly documented as yielding the SSL VPN session file containing usernames and passwords in plaintext. Any organization running the SSL VPN web portal on a FortiGate appliance is affected, and risk is highest where the portal is directly reachable from the internet. The flaw is confirmed in the wild: it was added to the CISA KEV catalog on 2021-11-03 with known ransomware use, and EPSS assigns it a 100% probability of exploitation within 30 days. No public PoC is listed in the provided data, but credential theft tied to this bug has been widely reused by threat actors. Do: Apply the patched FortiOS release per Fortinet's vendor advisory immediately, as this is a CISA KEV required action; if the fixed version is not known from this data, follow Fortinet's FG-IR-18-384 advisory for the correct upgrade path. Rotate SSL VPN credentials and review VPN access logs for path-traversal requests, since successful exploitation exposes plaintext session credentials, and restrict SSL VPN portal exposure to trusted sources where possible. | 9.8 | 100% | KEV ransomware |
| mass≈500,000 internet-exposed FortiOS SSL VPN portals (Fortinet cited ~480,000 affected devices) | |
| CVE-2022-40684 | Admin-Interface Auth Bypass in Fortinet FortiOS, FortiProxy & FortiSwitchManager Fortinet's FortiOS, FortiProxy, and FortiSwitchManager contain an authentication bypass vulnerability (CWE-288) that lets an unauthenticated remote attacker gain access to the administrative interface. It is triggered by sending specially crafted HTTP or HTTPS requests directly to the admin interface, with no credentials or exploit code required. By bypassing authentication, an attacker can perform administrative operations on the device, such as modifying configuration or creating privileged accounts. Any organization running the affected products is exposed, particularly where the management interface is reachable from the internet. The flaw is being actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-10-11 with known ransomware use, and EPSS assigns it roughly a 100% probability of exploitation within 30 days, although no public PoC is known. Do: Upgrade FortiOS, FortiProxy, and FortiSwitchManager to the fixed releases identified in Fortinet's advisory per the KEV required action. As mitigation, restrict access to the admin interface (e.g., disable WAN-facing management and use local-in policies or allow-lists for management IPs). Review admin logs and device configuration for signs of unauthorized access, such as unexpected admin accounts, added SSH keys, or config changes. | 9.8 | 100% | KEV ransomware PoC ×2 |
| massHundreds of thousands of internet-exposed Fortinet admin interfaces (~300k+ exposed FortiGate/FortiProxy management interfaces observed in public scans around… |
Full article827 words · extracted from helpnetsecurity.com · click to collapse
A threat actor has leaked configuration files (aka configs) for over 15,000 Fortinet Fortigate firewalls and associated admin and user credentials.

The collection has been leaked on Monday and publicized on an underground forum by the threat actor that goes by “Belsen_Group”, supposedly as a free offering to solidify the name of the group in the forum users’ memory.
The leaked 1.6 GB archive contains folders ordered by country, and inside each are folders named after IP addresses. Inside those are full configuration files and a txt file with a list of admin and VPN user credentials.
“Most of the FortiNet configurations, namely 1603, were captured by the attackers in Mexico, 679 in the USA and 208 in Germany,” German news outlet Heise Online revealed.
Many of the affected devices are apparently located in companies and medical practices, they found. “As many as 80 different device types can be found in the data leak, with the FortiGate Firewall 40F and 60F being the most widespread. There are also WLAN gateways and devices for installation in the server rack as well as compact devices for the desk or broom cupboard.”
What to do?
According to several researchers, the archive with the stolen config files dates back to October 2022, and it’s believed that the attackers exploited an authentication bypass FortiOS vulnerability – CVE-2022–40684 – to assemble it.
“I’ve done incident response on one device at a victim org, and exploitation was indeed via CVE-2022–40684 based on artefacts on the device. I’ve also been able to verify the usernames and password seen in the dump matches the details on the device,” security researcher Kevin Beaumont shared.
CloudSEK researchers have downloaded the archive and have compiled the list of IP addresses that organizations can use to check whether their devices are among those that were affected.
“Exposure of usernames and passwords (some in plaintext) enables attackers to directly access sensitive systems. Even if organizations patched this CVE in 2022 after the patch was released by Fortigate, they still need to check for signs of compromise, as this was a zero-day,” the researchers noted.
Firewall rules can reveal internal network structures, potentially enabling attackers to bypass defenses, they added. “Breached digital certificates could allow unauthorized device access or impersonation in secure communications.”
They have advised organizations to update all device and VPN credentials, review firewall rules for exploitable weaknesses and tighten access controls, revoke and replace all exposed digital certificates to restore secure communications and, finally, do a forensic investigation to check whether the devices have been or are still compromised.
They posit that the Belsen Group has used the leaked information themselves or sold it on to other attackers prior to leaking it.
“Belsen Group may seem new to the forums, but based on the data leaked by them, we can ascertain with high confidence that they’ve been around for at least 3 years now. They were likely part of a threat group that exploited a zero day in 2022, although direct affiliations have not been established yet,” they concluded.
UPDATE (January 17, 2025, 08:45 a.m. ET):
According to Fortinet, it’s “highly likely” that the leaked data was obtained by leveraging CVE-2022-40684 to achieve initial access to targeted devices, and CVE-2018-13379 to extract sensitive data from them.
“The threat actor has leaked data obtained in dated campaigns that has been aggregated to appear like a new disclosure. Our analysis of the devices in question show that the majority have long since upgraded to newer versions,” the company said.
“Whilst this data is several years old and the IP addresses have been observed to no longer be relevant in many cases, we will be reaching out to any customers, where identified, to recommend to review configurations.”
Beaumont has analyzed the leaked data, which covers 15,474 FortiOS devices, and found that the majority of the data is related to “SMBs using telco or business leased line services,” but there is some associated with large companies and governments.
Conspicuously missing is data related to devices in Iran and Russia, he also pointed out.
UPDATE (January 23, 2025, 10:20 a.m. ET):
Beaumont has listed the IP and email addresses extracted from the leaked configs, and security researcher Florian Roth has sorted the associated domains by TLD.
“Some of these domains may just be the domains of free email services or services providers working for the actual victims,” Roth noted, but both list can come handy to those organizations that have added a corporate email address to the config files.
“One other side effect of the FortiGate config incident is there’s several thousand site to site IPsec VPN configs allowing you to straight up join to the internal network of large orgs,” Beaumont added. “So even if you weren’t popped, the threat actor can pop up on your network.”

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/01/16/leaked-fortinet-fortigate-configs-vpn-credentials-ip-list/