Researchers find older versions of Fortinet's firewall software allow remote access using a hard-coded password; company says issue resolved via patch in 2014
Et tu, Fortinet? Hard-coded password raises new backdoor eavesdropping fears — Discovery comes a month after competitor Juniper disclosed unauthorized code.
Context & Ripple Effects
A month after Juniper found unauthorized code in its NetScreen firewalls that could decrypt VPN traffic, researchers surface the same class of flaw at Fortinet: older firewall software versions contain a hard-coded password permitting remote access. Fortinet says a 2014 patch resolved it — which means the live risk sits almost entirely in customers who never upgraded.
The timing compounds the damage. Two of the largest perimeter-security vendors disclosing hidden access paths within weeks turns 'trust the appliance' into an open procurement question, especially with researchers showing attackers can build their own backdoor on top of an existing one, as happened with Juniper's ScreenOS.
First-order effects
- Fortinet customers still running pre-2014 firmware on internet-facing firewalls hold devices remotely accessible with a publicly known password until they upgrade — the vendor's fix protects only those who applied it.
- The disclosure lands while Juniper's incident is still fresh, forcing both vendors' enterprise customers to weigh whether their perimeter gear can be trusted without independent verification.
Second-order effects
- Hard-coded credentials become a priority audit target across the appliance category: once one vendor's embedded key surfaces, researchers know exactly where to look next — a pattern later confirmed when [[a:1160486|over 100K Zyxel firewalls and VPN gateways were found with a hardcoded admin-level backdoor]].
- Rival firewall makers face the same source-code scrutiny by association, and buyers begin demanding provenance guarantees rather than patch notes as the basis of trust.
Third-order effects
- Disclosure alone doesn't close exposure: Fortinet's later record — a 2022 authentication bypass already under exploitation ([[a:983715]]) and roughly 336K of ~490K affected SSL VPN interfaces still unpatched months after a fix — shows the un-upgraded installed base, not the vulnerability report, is the durable weakness.
- If hidden-access discoveries keep recurring across vendors, perimeter appliances get treated as inherently suspect infrastructure, shifting the market toward vendors willing to undergo independent code review and toward architectures that assume the gateway itself may be compromised.
The trend: Network security vendors are being repeatedly exposed as single points of hidden-access failure, making independent code audits and actual patch uptake — not vendor assurances — the operative trust mechanism for enterprise perimeters.