bk99.de entertain the web since 1997

Ongoing attacks endanger 10,000 firewalls

Summary

At the end of 2025 Fortinet warned of ongoing attacks on a FortiOS hole patched since July 2020 (CVE-2020-12812), which according to Shadowserver was still exploitable on around 10,000 firewalls. Attackers use it to bypass two-factor login via FortiToken by changing the upper and lower case of the user name. Local users authenticated via LDAP and assigned to a group are affected.

Ideas

  • Different handling of upper and lower case between systems opens a hole.
  • A five-year-old patch is useless if it is not installed.
  • As an alternative, Fortinet recommended disabling the “username-case-sensitivity” option.
  • Vulnerable systems should be considered potentially compromised.

Insights

  • Two-factor authentication is only as strong as the user name check before it.
  • Old, known holes remain a main attack path on perimeter devices.

Facts

  • FortiOS up to 6.4.0, 6.2.3 and 6.0.9 is affected; fixed in 6.4.1, 6.2.4 and 6.0.10.
  • On 4 January 2026, 9,658 systems were still vulnerable, 48 of them in Germany.

References

Critique

  • The report does not say what the ongoing attacks look like in concrete terms or who is behind them.

Recommendations

  • Check firewalls for outdated firmware, even if the hole is years old.
  • Treat a firewall that has long been vulnerable as compromised and examine accounts and configuration.

Read the original article

Search the Web Archive