Hidden functionality issue exists in FF-RFI079I4 and FF-RFI078I4, which may allow a user who can log in via SSH and access the enable mode on the product to execute arbitrary OS commands.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-80217 represents a critical privilege escalation vulnerability affecting FF-RFI079I4 and FF-RFI078I4 devices. The vulnerability exploits undocumented or hidden functionality that becomes accessible once an attacker has gained SSH login credentials and enable mode access. With a CVSS score of 8.8, this allows authenticated threat actors to execute arbitrary OS commands with elevated privileges, potentially leading to complete system compromise, data exfiltration, or lateral movement within critical infrastructure environments. Organizations running these Fortinet Fortigate devices should prioritize patch deployment and restrict SSH access to trusted administrative networks.
While Casky.ai currently shows zero mapped skills for this specific CVE, practitioners using the platform would benefit from its Claude AI-powered extended reasoning capabilities to identify related attack patterns. Detection would focus on monitoring for CWE-912 (Hidden Functionality) indicators: unusual enable mode access attempts, unexpected command execution from SSH sessions, and anomalous system calls post-authentication. Security teams should leverage Casky's 754 mapped MITRE ATT&CK skills to hunt for related techniques such as T1134 (Access Token Manipulation), T1548 (Abuse Elevation Control Mechanism), and T1059 (Command and Scripting Interpreter) when analyzing SSH and enable mode activity logs. As this CVE is not yet in the CISA KEV catalog, proactive threat hunting and behavioral analytics remain essential until public exploitation increases.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-80217. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation