
Go-based exploit tool for CVE-2022-40684 (Fortinet authentication bypass). Automates SSH key injection for authorized penetration testing and vulnerability verification on Fortinet devices.
Quick exploitation tool for CVE-2022-40684, beginner code, feel free to submit issues if you find any
main -t http://127.0.0.1 -u admin -f path-of-ssh-key.pub
This tool is only intended for legally authorized enterprise security practices, such as internal attack/defense exercises, vulnerability verification and re-testing. If you need to test the usability of this tool, please set up your own target environment.
When using this tool for testing, you should ensure that the activity complies with local laws and regulations and that sufficient authorization has been obtained. Do not use it against unauthorized targets.
If you engage in any illegal behavior while using this tool, you must bear the corresponding consequences yourself. We will not assume any legal or joint liability.