FortiOS CVE-2025-68686: Bypass of Symlink Persistence Mitigation for Already Compromised Devices
1. Basic Information
- Article Name: CISA Adds Two Known Exploited Vulnerabilities to Catalog
- Source: CISA
- Publication Date: July 27, 2026
- Original Link: https://www.cisa.gov/news-events/alerts/2026/07/27/cisa-adds-two-known-exploited-vulnerabilities-catalog
- Related Sources:
- Related Entities: CVE-2025-68686, FortiOS, SSL-VPN, symlink persistence, CISA KEV
- Severity: Critical
2. Summary
This is an actively exploited vulnerability. An attacker who has already compromised the FortiOS file system via another vulnerability can use a crafted HTTP request to bypass symlink persistence mitigations. This allows access to sensitive files through the SSL-VPN web interface even after an upgrade.
3. Attack Flow
- An attacker compromises FortiOS down to the file system level using another vulnerability or path.
- The attacker places a symlink pointing to out-of-bounds system files into the SSL-VPN related area.
- An administrator applies standard patches or firmware updates, but the malicious symlink or its recreation path remains.
- The attacker bypasses the mitigation using a crafted HTTP request via CVE-2025-68686.
- The attacker may read sensitive files such as configurations, credentials, and keys from the SSL-VPN web interface.
- The attacker may use the stolen information to continue VPN authentication, administrative access, and internal intrusion.
4. Attacker Position and Execution Location
- Initial compromise and symlink placement happen on the FortiGate/FortiOS device.
- Mitigation bypass and file reading occur externally via the SSL-VPN HTTP(S) interface.
- This CVE alone does not provide initial file system access to uncompromised devices.
5. Visibility for Victims and Administrators
- The device may look updated, but unauthorized symlinks can remain.
- Crafted HTTP requests to the SSL-VPN web interface and unexpected file access.
- After reading configurations, credentials, and keys, subsequent activities may appear as legitimate VPN authentication.
6. Success and Failure Conditions
Success Conditions
- The attacker has previously compromised FortiOS at the file system level.
- Affected versions are used (FortiOS 6.4, 7.0, 7.2, 7.4.0–7.4.6, 7.6.0–7.6.1).
- The SSL-VPN web interface is reachable, and symlink artifacts remain or can be recreated.
Failure Conditions
- Updating to fixed versions (7.4.7, 7.6.2, or later; check vendor table) and removing compromise artifacts.
- Restricting reachability to the SSL-VPN/management interface or disabling it when not needed.
- Rebuilding the device and rotating credentials and keys.
7. What Happens on Success
Sensitive files on FortiOS are exposed externally. VPN credentials, configurations, and keys can be used for follow-up compromises. While CISA’s KEV addition shows evidence of active exploitation, public information does not reveal the attackers, scale, or specific files stolen. Simply applying patches does not always remove existing compromises.
8. Observable Logs
- Email: None.
- Proxy/SWG/DNS: Abnormal HTTP requests to the SSL-VPN web interface, known attack sources (unpublicized), and external access continuing after updates.
- Endpoint/EDR: Usually difficult to deploy. Look for symlinks, web directories, configuration differences, file timestamps, and process/persistence artifacts.
- Identity/IdP: FortiGate management and SSL-VPN authentication, unknown IP addresses or countries, dormant accounts, and MFA anomalies.
- SaaS/Cloud: Management changes in FortiGate Cloud, API access, and backup downloads.
- Network: Internal discovery after SSL-VPN connection, lateral movement, credential reuse, and egress traffic.
9. Determining Attack Success
Stage Evidence Contact SSL-VPN web requests only Prior Compromise File system modification, symlinks, unknown files Bypass Attempt Crafted HTTP requests and symlink references Information Access Sensitive file reads and response sizes Successful Authentication VPN/admin login using stolen credentials Follow-up Compromise Internal discovery, lateral movement, data access10. Investigation Playbook
- Trigger: KEV-targeted versions, past FortiGate compromises, abnormal symlinks, and suspicious SSL-VPN access after updates.
- Initial Check: Check versions, public SSL-VPN exposure, past vulnerabilities/compromises, update history, and configuration backups.
- Endpoints: Preserve the file system, symlinks, web directories, logs, and timestamps using TAC/vendor procedures. Do not apply simple CLI procedures to unknown versions.
- Authentication/Cloud: Check VPN, administrators, APIs, MFA, locations, concurrent sessions, and the use of secrets.
- Follow-up Actions: Track internal traffic originating from VPN IP pools, AD authentication, lateral movement, and data access.
- Containment: Restrict/stop SSL-VPN, apply patches, re-image compromised devices, rotate all related secrets, and revoke MFA and sessions.
- Classification: Vulnerable / Prior Compromise / Persistence Present / File Access / Credential Abuse / Internal Compromise.
11. Defense and Detection Ideas
- Include checks for symlinks, configurations, and credential compromises as part of the patching process, not just firmware version checks.
- Save file system and configuration hash differences before and after updates.
- Correlate successful SSL-VPN authentication with internal discovery and administrative access in chronological order.
- Forward appliance logs to an external SIEM in real time to prepare for log deletion on the device.
12. Facts / Inference / Hypothesis
- Facts: CVSS score is 5.9. Prior file system compromise is required. CISA added it to KEV on July 27, 2026, with a due date of August 10, 2026.
- Inference: Practical risk is higher than the base score. Perimeter devices with past compromises require immediate incident response.
- Hypothesis: The combination of “an updated system plus unauthorized symlinks and abnormal SSL-VPN access” indicates ongoing compromise.
13. MITRE ATT&CK Mapping
- T1190 Exploit Public-Facing Application (High, Initial Access / Defense Evasion)
- T1546 Event Triggered Execution (Low, exact classification of symlink persistence requires review)
- T1005 Data from Local System (High)
- T1552 Unsecured Credentials (High, when credential files are retrieved)
- T1133 External Remote Services (Medium, subsequent VPN use)
- T1078 Valid Accounts (Medium)
14. Unknowns and Additional Investigation
HTTP formats of active exploits, attack sources, initial intrusion CVEs, symlink paths, retrieved files, scale of victims, and complete compromise confirmation procedures.
15. Impact on SOCs and General Organizations
FortiGate devices are widely used as perimeter security devices in corporate networks and branch offices, where EDR visibility is often low. Devices that exposed vulnerable SSL-VPNs in the past cannot be considered safe based on the current software version alone. Organizations need to conduct compromise assessments, including device rebuilding and the rotation of secrets.
16. Summary by Target Audience
- For SOCs: Track past compromises, symlinks, SSL-VPN reads, credential usage, and internal traffic as a connected sequence.
- For Administrators: Verify artifacts using vendor procedures in addition to applying patches. If suspicious, re-image the device and rotate all secrets.
- For Users: Immediately report suspicious MFA and login notifications, and do not approve them on your own judgment.
답글 남기기