FGFM Authentication Weakening via CLI Configuration
Plan PatchCVSS 7.3FG-IR-26-160Aug 12, 2026
Fortinet
IT in OT - Fortinet products are commonly deployed at IT/OT network boundaries
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityHigh
User InteractionNone needed
Summary
Fortinet FortiManager versions 7.6.1, 7.4.3–7.4.5, and 7.2.5–7.2.9 contain an authentication weakness in the CLI configuration interface that allows attackers to bypass authentication and issue commands without valid credentials. An attacker can exploit this to reconfigure FortiManager to accept and trust unauthorized Fortinet devices, effectively impersonating legitimate managed firewalls and gaining control over network security policies and traffic handling.
What this means
What could happen
An attacker with network access to FortiManager could bypass authentication and issue commands that make it accept unauthorized Fortinet devices, allowing the attacker to masquerade as a trusted firewall and intercept or redirect traffic destined for your protected networks.
Who's at risk
Organizations running FortiManager (on-premises or cloud) for centralized Fortinet firewall management. This includes utilities and manufacturing plants using Fortinet security appliances to protect industrial control systems or SCADA networks from external threats.
How it could be exploited
An attacker sends specially crafted CLI commands to FortiManager over the network (requiring guessing or brute-forcing conditions, hence AC:H complexity). Once authentication is bypassed, the attacker can reconfigure FortiManager to trust malicious Fortinet devices as legitimate managed firewalls, gaining control over traffic policies and network behavior.
Prerequisites
- Network access to FortiManager CLI port (typically SSH port 22 or administrative interface)
- Ability to craft and submit CLI commands; no valid credentials required for initial bypass
- FortiManager running vulnerable version (7.6.1, 7.4.3–7.4.5, or 7.2.5–7.2.9)
remotely exploitableno authentication requiredhigh CVSS score (7.3)affects device trust relationships—critical for network security architecture
Exploitability
Unlikely to be exploited — EPSS score 0.7%
Affected products (6)
6 with fix
ProductAffected VersionsFix Status
FortiManager7.6.17.6.2+
FortiManager7.4.3 - 7.4.57.4.6+
FortiManager7.2.5 - 7.2.97.2.10+
FortiManager Cloud7.6.17.6.2+
FortiManager Cloud7.4.3 - 7.4.57.4.6+
FortiManager Cloud7.2.5 - 7.2.97.2.10+
Remediation & Mitigation
0/4
Do now
0/2FortiManager
WORKAROUNDIf update cannot be performed immediately, restrict network access to FortiManager CLI and administrative ports to authorized management stations only using firewall rules or network segmentation
HARDENINGAudit all Fortinet devices currently registered or managed by FortiManager to confirm they are legitimate and authorized; remove any suspicious or unrecognized devices
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
FortiManager
HOTFIXUpdate FortiManager to patched version: 7.6.2 or later, 7.4.6 or later, or 7.2.10 or later depending on your current version
Long-term hardening
0/1FortiManager
HARDENINGMonitor FortiManager logs for unauthorized CLI commands or new device registrations; alert on any changes to device trust relationships
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/0cc55f83-0217-4ca0-bb95-2e539fae494dGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.