Attackers are using FortiMail’s public management interface for credential-free file writes and appliance code execution.
Fortinet FortiMail, a physical, virtual and cloud-deployed secure email gateway.
A crafted HTTP or HTTPS request combines path traversal with NULL-byte handling to write or replace files outside the intended path.
Detail and 4 sources
Observed compromises included attacker-added binaries, ld.so.preload modification and root cron activity.
A patch was announced, but current release availability could not be resolved from the retrieved vendor material.
Today’s change is the confirmed scope: the arbitrary-file-write primitive is now connected to persistence and command execution using root-level mechanisms.