Fortinet FortiWeb Flaw: Admin Accounts at Risk in WAF Security Comedy of Errors

A vulnerability in Fortinet Fortiweb WAF is causing alarm bells to ring in the cybersecurity world. Hackers are exploiting this flaw to create admin accounts faster than you can say “Oh no!” If you’re running anything older than version 8.0.2, it’s time to patch up before your device becomes a hacker’s playground!

Pro Dashboard

Hot Take:

Well, Fortinet, it seems like your FortiWeb WAF has officially joined the “Oops, I did it again” club of cybersecurity blunders. Not only are attackers staging a hostile takeover of admin accounts, but they’re also making themselves comfy as if they own the place. With exploits flying around like confetti at a parade, Fortinet better hope their next patch doesn’t come with a side of vulnerability soup!

Key Points:

  • Authentication bypass vulnerability found in Fortinet FortiWeb WAF.
  • Attackers can add new admin accounts, effectively taking over the device.
  • Vulnerability patched in version 8.0.2 but was silently exploited in the wild.
  • Proof-of-concept and artifact generator tool released by cybersecurity researchers.
  • Fortinet yet to release an official advisory or CVE identifier.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?