What happened
FortiGate standard key allows decryption of user passwords, private keys, and HA passwords.
Affected versions
Unknown product: See original advisory Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
SploitusFortiGate standard key allows decryption of user passwords, private keys, and HA passwords.KitPloit2026-09-04T07:46:31Verifiedkitploit.comFortiGate standard key allows decryption of user passwords, private keys, and HA passwords.ru2026-09-04T07:46:31Candidatesynacktiv/CVE-2020-9289Decrypt reversible secrets encrypted using the default hardcoded key related to CVE-2020-9289 on FortiAnalyzer/FortiManager (the only difference with CVE-2019-6693 is the encryption routine).★ 11synacktiv2023-06-30VerifiedSource timeline
Discovered through SploitusView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.