
Python-based detector for FortiWeb authentication bypass (CVE-2025-xxxxx). Sends exploit payload to create a test user as proof of exploitation.
Detection Artifact Generator for FortiWeb Authentication Bypass
See our blog post for technical details
python watchTowr-vs-Fortiweb-AuthBypass.py 192.168.1.99
__ ___ ___________
__ _ ______ _/ |__ ____ | |_\__ ____\____ _ ________
\ \/ \/ \__ \ ___/ ___\| | \| | / _ \ \/ \/ \_ __ \
\ / / __ \| | \ \___| Y | |( <_> \ / | | \/
\/\_/ (____ |__| \___ |___|__|__ | \__ / \/\_/ |__|
\/ \/ \/
watchTowr-vs-Fortiweb-AuthBypass.py
(*) FortiWeb Authentication Bypass Artifact Generator
- Sina Kheirkhah (@SinSinology) and Jake Knott (@inkmoro) of watchTowr (@watchTowrcyber)
CVEs: [CVE-2025-xxxxx]
[+] Exploit sent successfully.
[*] Check for the new user [ 35f36895 ] with password [ 35f36895 ]
This script attempts to detect if FortiWeb is vulnerable to Authentication Bypass
FortiWeb Versions Below 8.0.2 are affected, for more specific versions please contact FortiGuard Labs PSIRT
For the latest security research follow the watchTowr Labs Team