
Erkennt die CVE-2025-64446-Authentifizierungsumgehung in FortiWeb durch die Ausnutzung eines Path Traversal, um die Schwachstelle zu bestätigen, ohne administrative Aktionen.
FortiWeb-Auth-Bypass-Scanner von Bishop Fox
Weitere Informationen zu dieser Schwachstelle finden Sie im Bishop-Fox-Blog.
git clone https://github.com/BishopFox/fortiweb-auth-bypass-check
cd fortiweb-auth-bypass-check
python3 -m pip install requests
python3 scan.py https://[TARGET]
# Vulnerable target
$ python3 scan.py https://example1.com
[*] Testing https://example1.com
[!] Target is VULNERABLE - update immediately!
# Unaffected target
$ python3 scan.py https://example2.com
[*] Testing https://example2.com
[+] Target is not affected
# Invalid target
$ python3 scan.py https://example3.com
[*] Testing https://example3.com
[-] Target does not appear to be FortiWeb
Dieser Code wird unter einer MIT-Lizenz verteilt.