FortiGate CVE-2025-25249 Unauthenticated Admin API POST Without Session Cookie

Detects unauthenticated HTTP POST requests targeting the FortiGate administrative API (/api/v2/), which may indicate exploitation attempts related to CVE-2025-25249. The rule specifically looks for requests lacking authentication headers (Cookie or Authorization).