Fortigate are calling this issue in FortiOS a “vulnerability” but to be clear it’s actually a major backdoor.

The backdoor code is flat out there in the OS, it even needs a ‘secret’ code typed to trigger it.

How did a major firewall vendor (almost 500k IPs) end up backdoored? twitter.com/gossithedog/status

