Werkzeug zur Erkennung und Ausnutzung von CVE-2025-25257 in Fortinet FortiWeb.
Credits
Based on watchTowr Labs, 0xbigshaq, and pwner.gg analyses.
Warnungen
For educational purposes only. Use on authorized systems. Modifies database/filesystem.
Verbessertes Python-Tool zur Erkennung und Ausnutzung von CVE-2025-25257 (Pre-Auth SQLi zu RCE in Fortinet FortiWeb).
python exploit.py --host target.com --https --exploit
--host: Target host.
--https: Use HTTPS.
--exploit: Perform exploit if vulnerable.
Installation
pip install -r requirements.txt