Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-59718-Fortinet-Poc — PoC para determinar si Fortinet es vulnerable a CVE-2025-59718 / CVE-2025-59719 | Kitploit
Tools/GitHubGitHub/moften/cve-2025-59718-fortinet-poc
ReconnaissanceVulnerability ScannersExploitationInformation GatheringNetwork SecurityPenetration Testing
GitHubmoften/cve-2025-59718-fortinet-poc

CVE-2025-59718-Fortinet-Poc

PoC para determinar si Fortinet es vulnerable a CVE-2025-59718 / CVE-2025-59719

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository
3139 months agoNot yet reviewed

CVEs: CVE-2025-59718 / CVE-2025-59719 Fortinet PoC

Tool for detecting vulnerabilities associated with CVE-2025-59718 and CVE-2025-59719 on Fortinet devices (FortiOS / FortiGate), using multiple identification techniques: passive, active, and authenticated.

Supports: • Passive detection by fingerprinting • Active verification (non-destructive) • Authenticated SSH connection • Mass scanning via file • Structured results export (JSON)


Usage

Most reliable verification (WITH active tests) ⭐ RECOMMENDED

python3 main.py --mode passive --target firewall.company.com --active-test

SSH mode (most reliable)

python3 main.py --mode ssh --target 192.168.1.1 --user admin --password 'MyPass123'

Multiple targets via file

python3 main.py --mode ssh --targets targets.txt --user admin --keyfile ~/.ssh/fw_key

Passive mode (no credentials)

python3 main.py --mode passive --target https://firewall.company.com

Save results to JSON

python3 main.py --mode passive --targets ips.txt --json results.json

Silent scanning (JSON only)

python3 main.py --mode passive --target firewall.company.com --json out.json --quiet

Mass scanning with active tests

python3 main.py --mode passive --targets ips.txt --active-test --json results.json

🎨 Example Output:

[*] [1/3] Escaneando 192.168.1.1...
[*] Conectando vía SSH a 192.168.1.1:22...

======================================================================
Target: 192.168.1.1
Mode: ssh
Verdict: [!!!] VULNERABLE - EXISTS
Confidence: high
Product: FortiOS
Version: 7.4.5
Patch Version: 7.4.9 or higher
FortiCloud SSO: ENABLED

Indicators:
  • Producto detectado: FortiOS v7.4.5
  • ⚠️  Versión 7.4.5 está en rango VULNERABLE
  • ⚠️  FortiCloud SSO login está HABILITADO

Notes:
  • Actualizar a versión 7.4.9 o superior
  • 🚨 CRÍTICO: Sistema VULNERABLE y FortiCloud SSO HABILITADO
  • 🚨 Este sistema está siendo explotado activamente in-the-wild
  • 🚨 ACCIÓN INMEDIATA REQUERIDA
======================================================================

🙌 Buy me a coffee?

If this tool has been useful to you or you want to support future development, you can buy me a coffee ☕ or make a donation. Any support counts!

Donate with PayPal


📬 Contact and social networks

  • 💌 Email: [email protected]
  • 🌐 Blog: https://m10.com.mx
  • 🐦 Twitter: @hack4lifemx
  • 💼 LinkedIn: Francisco Santibañez
  • 🐙 GitHub: github.com/m10sec

🛡️ Philosophy

I believe in a world where users have control over their privacy. This tool is born from the trenches of real pentesting, with love for digital freedom and hacking with purpose.


⭐ If you liked this project, give it a star on GitHub and share it with your community.

Download Tool