CVE-2025-55591
published 2025-08-18CVE-2025-55591: TOTOLINK-A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability in the devicemac parameter in the formMapDel endpoint.
PriorityP275critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
7.24%
93.6th percentile
TOTOLINK-A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability in the devicemac parameter in the formMapDel endpoint.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| totolink | a3002r_firmware | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
ET WEB_SPECIFIC_APPS Fortinet Authentication Bypass via Node.js Websocket (CVE-2024-55591)
suricata·2025-01-16·CVSS 9.8
CVE-2024-55591 [CRITICAL] ET WEB_SPECIFIC_APPS Fortinet Authentication Bypass via Node.js Websocket (CVE-2024-55591)
ET WEB_SPECIFIC_APPS Fortinet Authentication Bypass via Node.js Websocket (CVE-2024-55591)
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Fortinet Authentication Bypass via Node.js Websocket (CVE-2024-55591)"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/"; pcre:"/^\w+\-[a-zA-Z0-9]{6}$/R"; http.header; to_lowercase; content:"sec-websocket-key|3a 20|"; fast_pattern; content:"upgrade|3a 20|websocket"; content:!"origin|3a 20|http"; reference:url,github.com/watchtowrlabs/fortios-auth-bypass-check-CVE-2024-55591; reference:cve,2024-55591; classtype:web-application-attack; sid:2059283; rev:1; metadata:affected_product Fortigate, attack_target Server, tls_state TLSDecrypt, created_at 2025_01_16, cve CVE_2024_55591, deployment Perimet
No public exploits indexed.
Bleepingcomputer
Fortinet discloses second firewall auth bypass patched in January
blogs_bleepingcomputer·2025-02-11·CVSS 9.8
CVE-2025-24472 [CRITICAL] Fortinet discloses second firewall auth bypass patched in January
## Fortinet discloses second firewall auth bypass patched in January
## Sergiu Gatlan
Update 2/11/25 07:32 PM ET: After publishing our story, Fortinet has informed us that the new CVE-2025-24472 flaw added to FG-IR-24-535 today is not a zero-day and was already fixed in January.
Furthermore, even though today's updated advisory indicates that both flaws were exploited in attacks and even includes a workaround for the new CSF proxy requests exploitation pathway, Fortinet says that only CVE-2024-55591 was exploited.
Fortinet told BleepingComputer that if a customer previously upgraded based on the guidance in FG-IR-24-535 / CVE-2024-55591, then they are already protected against the newly disclosed vulnerability.
The title of our story has been updated to reflect this new information, a
Checkpoint
3rd February – Threat Intelligence Report
blogs_checkpoint·2025-02-03
CVE-2024-55591 3rd February – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 3rd February – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 3rd February, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
Mizuno USA, giant sports equipment manufacturer, has confirmed a cyber-attack that resulted in the theft of personal information from its network between August and October 2024. The data breach included names, Social Security numbers, financial account information, driver’s license details, and passport numbers. The Bian
2025-08-18
Published