⚠️ FortiWeb Authentication Bypass Vulnerability Let Attackers Log in As Any Existing User | Read more: https://lnkd.in/d3Zy4JW2 ✅ CVE-2025-52970 lets attackers bypass authentication to log in as any user on FortiWeb systems. ✅ FortiWeb 7.0-7.6 versions are vulnerable. ✅ Attackers manipulate cookie parameters to force zero-filled encryption keys. #cybersecuritynews #vulnerability
FortiWeb just became FortiOpen.
No surprise to me, they don't even think it's worth it to log API auth failures...
🙃 I feel safe 🥲
Kinda sounds like it should be higher than 7.7 on the scale.
Thanks for sharing
wow…
Thanks for highlighting this, always critical to stay ahead of such vulnerabilities. Organizations should prioritize patching and review their cookie security measures to avoid potential breaches. Stay safe out there!
Impersonate any user? Sounds like attackers just got VIP access.