Cyber Resilience

CVE-2016-1909

Fortinet Fortios ≤ 4.3.16

Public PoCHigh EPSS
Published
15 January 2016
Modified
06 May 2026
CVSS Score v3 9.8
Click a component to see what it means
Raw vectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.71 99.3th percentile
Risk Priority 97 floored blend · peak EPSS

Summary

CVE-2016-1909 is a critical-severity an unspecified weakness vulnerability in Fortinet Fortios. Its CVSS base score is 9.8 (Critical).

Operationally, ranked in the top 0.7% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.

EU & UK References

Vulnerability Data

Fortinet FortiAnalyzer before 5.0.12 and 5.2.x before 5.2.5; FortiSwitch 3.3.x before 3.3.3; FortiCache 3.0.x before 3.0.8; and FortiOS 4.1.x before 4.1.11, 4.2.x before 4.2.16, 4.3.x before 4.3.17 and 5.0.x before 5.0.8 have a hardcoded passphrase for the Fortimanager_Access account, which…

more

allows remote attackers to obtain administrative access via an SSH session.

CWE(s)

Related Threats

Likely ATT&CK TechniquesAI

Techniques this vulnerability likely enables, inferred from its description, weakness type, and attributed-actor tradecraft. Confidence is per-technique.

T1133 External Remote Services Persistenceconfidence: HIGH
Hardcoded administrative credentials enable remote attackers to authenticate via SSH and gain initial access.
T1078.001 Default Accounts Stealthconfidence: HIGH
The vulnerability provides a default administrative account that can be used for unauthorized access.
T1021.004 SSH Lateral Movementconfidence: HIGH
Attackers can leverage the exposed SSH service to establish remote interactive sessions.
inferred from description + CWE · MITRE ATT&CK Enterprise v19.0

CVEs Like This One

CVE-2020-12812Same product: Fortinet Fortios
CVE-2023-46717Same product: Fortinet Fortios
CVE-2023-46714Same product: Fortinet Fortios
CVE-2025-58325Same product: Fortinet Fortios
CVE-2024-26007Same product: Fortinet Fortios
CVE-2024-32122Same product: Fortinet Fortios
CVE-2025-53844Same product: Fortinet Fortios
CVE-2023-28001Same product: Fortinet Fortios
CVE-2025-25252Same product: Fortinet Fortios
CVE-2023-33301Same product: Fortinet Fortios

Affected Assets

fortinet
fortios
5.0, 5.0.0, 5.0.1, 5.0.2, 5.0.3 · ≤ 4.3.16

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References