CVE-2024-48887 is an unverified password-change vulnerability in the FortiSwitch GUI password-change functionality. Insufficient validation permits a remote unauthenticated attacker to submit a specially crafted request that modifies an administrator password. Affected releases are FortiSwitch 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.10, and 6.4.0 through 6.4.14.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository provides a proof-of-concept (PoC) exploit for CVE-2024-48887, a vulnerability in Fortinet FortiSwitch devices. The exploit consists of a single JavaScript file (main.js) that demonstrates how an attacker can send an unauthenticated HTTP POST request to the /change_pass endpoint of a vulnerable FortiSwitch device. By doing so, the attacker can change the password of the 'admin' user without prior authentication, potentially gaining full control over the device. The repository also includes a README.md that explains the vulnerability, its impact, and usage instructions. The exploit is simple, does not require authentication, and targets the network-exposed web management interface of FortiSwitch devices. No additional payloads or frameworks are used; the exploit is a standalone JavaScript snippet suitable for demonstration or testing purposes.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical FortiSwitch GUI vulnerability allowing unauthenticated remote password changes (admin password change flaw).
Critical Fortinet FortiSwitch GUI vulnerability caused by insufficient verification of password-change requests, allowing a remote unauthenticated attacker to change administrator credentials and potentially gain full control of the system.
A critical unverified password change vulnerability in the Fortinet FortiSwitch GUI that could allow a remote unauthenticated attacker to change administrator passwords via a crafted request.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.