What the CDSL Malware Attack Teaches Organizations About VAPT?
Most organizations believe that completing an annual Vulnerability Assessment and Penetration Testing...
Read more ›Fortinet has found itself at the center of an unauthorized access incident wherein the attackers have taken over full device control. The vulnerability detected in the OS was CVE-2025-22252(Missing Authentication for Critical Function) with a critical severity of 9.0 that allows an attacker knowledgeable of an existing admin account to access the device and bypass authentication.
It exists in FortiOS, FortiProxy, and FortiSwitchManager TACACS+ configured to use a remote TACACS+ server for authentication. After being discovered by Cam B from Vital and NBS Telecom’s Matheus, Fortinet quickly took action to prevent any further progress by the threat actor.
Under this threat, which products have been affected? Let’s find out.
As per the security advisory, three of the twelve products are affected. Here’s how they’ve summarized the effects and the action we can take.
| Affected Products | Remedy |
| FortiOS 7.6 | Upgrade to 7.6.1 or above |
| FortiOS 7.4 Through 7.4.6 | Upgrade to 7.4.7 or above |
| FortiProxy 7.6.0 Through 7.6.1 | Upgrade to 7.6.2 or above |
| FortiSwitchManager 7.2.5 | Upgrade to 7.2.6 or above |
Also read: Coinbase Data Breach: Bribery Leads to USD 400 Million Loss
Fortinet has assured that the current vulnerability is limited to configurations that require ASCII authentication. PAP, MSCHAP, and CHAP configurations are safe from the impact. Additionally, Fortinet offers two workarounds that do not use ASCII authentication, which can prevent the vulnerability from impacting other devices. This aims towards organizations who may not be able to make the upgrade sooner.
Also read: Everything you need to know about CDSL Malware attack
As an experienced cyber expert, Secucenter has seen how large-scale cybersecurity companies and their products are targeted to access client data for many negative reasons. Staying secure is not a one-time thing, but a recurrent requirement that needs attention. If you are an MSSP, then our dedicated SOC services are here to provide that extra layer of protection to your clients from current and future threats.
Most organizations believe that completing an annual Vulnerability Assessment and Penetration Testing...
Read more ›
In a world where cyber threats evolve faster than ever, Managed Service...
Read more ›
In today’s evolving cybersecurity landscape, Managed Service Providers (MSPs) face increasing pressure...
Read more ›Most breaches begin with a gap no one was watching. Tell us what you're protecting and our SOC analysts will pressure-test your defenses and show you exactly where you stand.
Phone
+1 607 360 5504
Sales Office - United States
651, N Broad St, Middletown
Delaware-19709
Operations Center- India
Level 17, TransAsia Cyber Park
Kochi, Kerala-682030
Data privacy notice.
All submissions are protected via TLS 1.3 encryption in transit and
processed within our secure, air-gapped data environment. We never resell your data.