/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researchers find older versions of Fortinet's firewall software allow remote access using a hard-coded password; company says issue resolved via patch in 2014

Et tu, Fortinet?  Hard-coded password raises new backdoor eavesdropping fears  —  Discovery comes a month after competitor Juniper disclosed unauthorized code.

Ars Technica Dan Goodin

Context & Ripple Effects

A month after Juniper found unauthorized code in its NetScreen firewalls that could decrypt VPN traffic, researchers surface the same class of flaw at Fortinet: older firewall software versions contain a hard-coded password permitting remote access. Fortinet says a 2014 patch resolved it — which means the live risk sits almost entirely in customers who never upgraded.

The timing compounds the damage. Two of the largest perimeter-security vendors disclosing hidden access paths within weeks turns 'trust the appliance' into an open procurement question, especially with researchers showing attackers can build their own backdoor on top of an existing one, as happened with Juniper's ScreenOS.

First-order effects

  • Fortinet customers still running pre-2014 firmware on internet-facing firewalls hold devices remotely accessible with a publicly known password until they upgrade — the vendor's fix protects only those who applied it.
  • The disclosure lands while Juniper's incident is still fresh, forcing both vendors' enterprise customers to weigh whether their perimeter gear can be trusted without independent verification.

Second-order effects

  • Hard-coded credentials become a priority audit target across the appliance category: once one vendor's embedded key surfaces, researchers know exactly where to look next — a pattern later confirmed when [[a:1160486|over 100K Zyxel firewalls and VPN gateways were found with a hardcoded admin-level backdoor]].
  • Rival firewall makers face the same source-code scrutiny by association, and buyers begin demanding provenance guarantees rather than patch notes as the basis of trust.

Third-order effects

  • Disclosure alone doesn't close exposure: Fortinet's later record — a 2022 authentication bypass already under exploitation ([[a:983715]]) and roughly 336K of ~490K affected SSL VPN interfaces still unpatched months after a fix — shows the un-upgraded installed base, not the vulnerability report, is the durable weakness.
  • If hidden-access discoveries keep recurring across vendors, perimeter appliances get treated as inherently suspect infrastructure, shifting the market toward vendors willing to undergo independent code review and toward architectures that assume the gateway itself may be compromised.

The trend: Network security vendors are being repeatedly exposed as single points of hidden-access failure, making independent code audits and actual patch uptake — not vendor assurances — the operative trust mechanism for enterprise perimeters.