
PoC (Proof of Concept) - Educational Use Only
Exploit for improper access to SD-WAN Orchestrator in FortiManager, exploiting access control flaw (CWE-284).
The CVE-2021-24006 vulnerability affects FortiManager (versions 6.4.0 to 6.4.3) and allows authenticated users with a restricted profile to directly access the SD-WAN Orchestrator dashboard URL, even without explicit permission via the interface.
Direct access to the vulnerable URL:
https://<IP>/fortiwan/maintenance/controller_configuration
This code is provided only for educational and awareness purposes.
Do not run in production environments or without explicit authorization.
CVE-2021-24006 fortinet fortimanager sd-wan exploit poc vulnerability access-control bypass