Build1 publisher2 min readPublished
Gunra enters through the same VPN appliances the advisory says should front RDP
Gunra affiliates get in through two FortiOS and FortiProxy authentication bypasses, CVE-2024-55591 and CVE-2025-24472, says a 10 August 2026 advisory. Its fix for exposed RDP routes remote access through that same class of appliance, so the gateway has to be secured before RDP moves behind it.
The Engineer · Build desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Once inside, Gunra actors used Impacket's psexec.py and smbclient.py to move across victim networks over SMB, according to the advisory as summarised on dev.to.
- In one intrusion they reached an internal virtual desktop environment and kept moving laterally over RDP.
- Another documented intrusion began with an SSL-VPN appliance administrator account reached through default credentials, on a device with no account lockout.
- For exposed RDP, the advisory's mitigation is to remove direct internet exposure and route remote access through a VPN or gateway device.
- ZoomEye counted 16,471,930 RDP-fingerprinted endpoints on 28 September 2026, and 15,686,374 when the query also required port 3389.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- decision Exposure removal and edge patching belong in one change plan for the gateway owner. Done months apart, either order leaves one entry open in between: exposed RDP, or RDP behind a gateway with a known bypass.
- cost Gateway owners owe a review of the appliance's accounts and lockout settings on top of the patch, because the default-credential entry still works on a fully patched device.
- constraint Edge work does not contain an affiliate who is already inside. Against Impacket over SMB and internal RDP, the advisory's only listed control is segmentation.
Put the advisory's RDP mitigation beside its initial-access finding and the same device appears twice. According to a dev.to write-up of the advisory, the VPN or gateway meant to front remote access [6] belongs to the firewall and VPN appliance class Gunra exploits to get in [2]. Moving RDP behind a gateway adds one authentication step. CVE-2024-55591 and CVE-2025-24472 are authentication bypasses in FortiOS and FortiProxy, so on an affected appliance that step can be skipped [2]. The default-credential intrusion needed no CVE at all, only an administrator account and a missing lockout policy [5].
The RDP in the lateral-movement account was internal. The hop came after the actors reached a virtual desktop environment inside the network [4]. The advisory summary does not document a Gunra intrusion that began on internet-exposed RDP. Exposed RDP enters the advisory through its first key action, which lists RDP-exposed infrastructure beside VPN gateways under patching known exploited flaws in internet-facing systems [1]. On this evidence the chain runs from gateway to SMB through Impacket [3], then to internal RDP. Edge patching and exposure removal cover the first link. The advisory's control for the rest is segmentation [7].
The dev.to post sizes the exposed side with ZoomEye counts. Requiring port 3389 drops 785,556 endpoints from the fingerprint count, about 4.8 percent of it [8][1][2]. The post attributes the gap to RDP on non-standard ports, or to fingerprint and port records that disagree [10]. That share is one scanner's global average. It holds for a particular estate only if that estate runs RDP off 3389 at the internet's rate. A fingerprint scan of the estate's own address ranges is the only way to check. The United States slice was 3,353,836, about a fifth of the total, and it inherits every error in IP geolocation [11][3]. None of these counts show that a host is unpatched, weakly credentialed or reached by a Gunra affiliate [9].
The advisory also calls for an offline, immutable backup in a physically separate, segmented location [12]. The post makes one engineering point I agree with: each of these mitigations has a test. Exposure can be confirmed from outside, lockout and segmentation by configuration review, and backup immutability by attempting a restore [13].
What to watch
- A documented Gunra intrusion that starts on internet-exposed RDP, which would add a second first link to the chain the advisory describes.
- A repeat ZoomEye count against the 28 September 2026 baseline of 16,471,930 RDP endpoints, showing whether exposure falls after the advisory.
- Further initial-access vectors from the advisory's issuer beyond the two FortiOS/FortiProxy bypasses and default SSL-VPN credentials.