Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2021-24006 — Proof-of-concept exploit for CVE-2021-24006, demonstrating improper access control bypass in FortiManager SD-WAN Orchestrator (versions 6.4.0-6.4.3). For authorized educational testing only. | Kitploit
Tools/GitHubGitHub/chessredoffsec/cve-2021-24006
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingMisconfigurationLearning & Education
GitHubchessredoffsec/cve-2021-24006

CVE-2021-24006

Proof-of-concept exploit for CVE-2021-24006, demonstrating improper access control bypass in FortiManager SD-WAN Orchestrator (versions 6.4.0-6.4.3). For authorized educational testing only.

View Repository
21481 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2021-24006 – FortiManager Improper Access Control Exploit (PoC)

PoC (Proof of Concept) - Educational Use Only
Exploit for improper access to SD-WAN Orchestrator in FortiManager, exploiting an access control flaw (CWE-284).


Description

The vulnerability CVE-2021-24006 affects FortiManager (versions 6.4.0 through 6.4.3) and allows authenticated users with a restricted profile to directly access the SD-WAN Orchestrator dashboard URL, even without explicit permission via the interface.

Direct access to the vulnerable URL:
https://<IP>/fortiwan/maintenance/controller_configuration


Affects

  • FortiManager 6.4.0 through 6.4.3
  • FortiManager 6.2.x and earlier are not affected

Prerequisites

  • FortiManager with SD-WAN Orchestrator installed
  • User with Restricted Admin profile
  • Access to the FortiManager Web interface

Exploitation (educational)

  1. Authenticate to the Web interface with a restricted profile user
  2. Visit the URL directly:

Mitigations

  • Upgrade to FortiManager 6.4.4 or higher
  • Alternatively, use version 7.0.0+
  • Restrict Web interface access by IP
  • Monitor logs for requests to the critical URL

Legal Notice

This code is provided for educational and awareness purposes only.
Do not run in production environments or without explicit authorization.


Tags

CVE-2021-24006 fortinet fortimanager sd-wan exploit poc vulnerability access-control bypass

Download Tool