Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2021-24006-Fortimanager-Exploit | Kitploit
Tools/GitHubGitHub/chessredoffsec/cve-2021-24006-fortimanager-exploit
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingMisconfigurationLearning & Education
GitHubchessredoffsec/cve-2021-24006-fortimanager-exploit

CVE-2021-24006-Fortimanager-Exploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository
11 year agoNot yet reviewed

CVE-2021-24006 – FortiManager Improper Access Control Exploit (PoC)

PoC (Proof of Concept) - Educational Use Only
Exploit for improper access to SD-WAN Orchestrator in FortiManager, exploiting access control flaw (CWE-284).


Description

The CVE-2021-24006 vulnerability affects FortiManager (versions 6.4.0 to 6.4.3) and allows authenticated users with a restricted profile to directly access the SD-WAN Orchestrator dashboard URL, even without explicit permission via the interface.

Direct access to the vulnerable URL:
https://<IP>/fortiwan/maintenance/controller_configuration


Affects

  • FortiManager 6.4.0 to 6.4.3
  • FortiManager 6.2.x and earlier are not affected

Prerequisites

  • FortiManager with SD-WAN Orchestrator installed
  • User with Restricted Admin profile
  • Access to the FortiManager Web interface

Exploitation (educational)

  1. Authenticate on the Web interface with a restricted profile user
  2. Directly visit the URL:

Mitigations

  • Update to FortiManager 6.4.4 or higher
  • Alternatively, use version 7.0.0+
  • Restrict access to the Web interface by IP
  • Monitor logs for requests to the critical URL

Legal Notice

This code is provided only for educational and awareness purposes.
Do not run in production environments or without explicit authorization.


Tags

CVE-2021-24006 fortinet fortimanager sd-wan exploit poc vulnerability access-control bypass

Download Tool