
PoC para determinar si Fortinet es vulnerable a CVE-2025-59718 / CVE-2025-59719
Tool for detecting vulnerabilities associated with CVE-2025-59718 and CVE-2025-59719 on Fortinet devices (FortiOS / FortiGate), using multiple identification techniques: passive, active, and authenticated.
Supports: • Passive detection by fingerprinting • Active verification (non-destructive) • Authenticated SSH connection • Mass scanning via file • Structured results export (JSON)
python3 main.py --mode passive --target firewall.company.com --active-test
python3 main.py --mode ssh --target 192.168.1.1 --user admin --password 'MyPass123'
python3 main.py --mode ssh --targets targets.txt --user admin --keyfile ~/.ssh/fw_key
python3 main.py --mode passive --target https://firewall.company.com
python3 main.py --mode passive --targets ips.txt --json results.json
python3 main.py --mode passive --target firewall.company.com --json out.json --quiet
python3 main.py --mode passive --targets ips.txt --active-test --json results.json
[*] [1/3] Escaneando 192.168.1.1...
[*] Conectando vía SSH a 192.168.1.1:22...
======================================================================
Target: 192.168.1.1
Mode: ssh
Verdict: [!!!] VULNERABLE - EXISTS
Confidence: high
Product: FortiOS
Version: 7.4.5
Patch Version: 7.4.9 or higher
FortiCloud SSO: ENABLED
Indicators:
• Producto detectado: FortiOS v7.4.5
• ⚠️ Versión 7.4.5 está en rango VULNERABLE
• ⚠️ FortiCloud SSO login está HABILITADO
Notes:
• Actualizar a versión 7.4.9 o superior
• 🚨 CRÍTICO: Sistema VULNERABLE y FortiCloud SSO HABILITADO
• 🚨 Este sistema está siendo explotado activamente in-the-wild
• 🚨 ACCIÓN INMEDIATA REQUERIDA
======================================================================
If this tool has been useful to you or you want to support future development, you can buy me a coffee ☕ or make a donation. Any support counts!
I believe in a world where users have control over their privacy. This tool is born from the trenches of real pentesting, with love for digital freedom and hacking with purpose.
⭐ If you liked this project, give it a star on GitHub and share it with your community.