Ongoing attacks endanger 10,000 firewalls
Summary
At the end of 2025 Fortinet warned of ongoing attacks on a FortiOS hole patched since July 2020 (CVE-2020-12812), which according to Shadowserver was still exploitable on around 10,000 firewalls. Attackers use it to bypass two-factor login via FortiToken by changing the upper and lower case of the user name. Local users authenticated via LDAP and assigned to a group are affected.
Ideas
- Different handling of upper and lower case between systems opens a hole.
- A five-year-old patch is useless if it is not installed.
- As an alternative, Fortinet recommended disabling the “username-case-sensitivity” option.
- Vulnerable systems should be considered potentially compromised.
Insights
- Two-factor authentication is only as strong as the user name check before it.
- Old, known holes remain a main attack path on perimeter devices.
Facts
- FortiOS up to 6.4.0, 6.2.3 and 6.0.9 is affected; fixed in 6.4.1, 6.2.4 and 6.0.10.
- On 4 January 2026, 9,658 systems were still vulnerable, 48 of them in Germany.
References
Critique
- The report does not say what the ongoing attacks look like in concrete terms or who is behind them.
Recommendations
- Check firewalls for outdated firmware, even if the hole is years old.
- Treat a firewall that has long been vulnerable as compromised and examine accounts and configuration.
Links to the original source and the Web Archive open in a new tab.