Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
watchTowr-vs-Fortiweb-AuthBypass — Python-based detector for FortiWeb authentication bypass (CVE-2025-xxxxx). Sends exploit payload to create a test user as proof of exploitation. | Kitploit
Tools/GitHubGitHub/watchtowrlabs/watchtowr-vs-fortiweb-authbypass
Vulnerability AnalysisExploitationWeb Application ExploitationWAF BypassPenetration Testing
GitHubwatchtowrlabs/watchtowr-vs-fortiweb-authbypass

watchTowr-vs-Fortiweb-AuthBypass

Python-based detector for FortiWeb authentication bypass (CVE-2025-xxxxx). Sends exploit payload to create a test user as proof of exploitation.

View Repository
76132010 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

watchTowr-vs-Fortiweb-AuthBypass

Detection Artifact Generator for FortiWeb Authentication Bypass

See our blog post for technical details

Detection in Action

python watchTowr-vs-Fortiweb-AuthBypass.py 192.168.1.99
                         __         ___  ___________
         __  _  ______ _/  |__ ____ |  |_\__    ____\____  _  ________
         \ \/ \/ \__  \    ___/ ___\|  |  \|    | /  _ \ \/ \/ \_  __ \
          \     / / __ \|  | \  \___|   Y  |    |(  <_> \     / |  | \/
           \/\_/ (____  |__|  \___  |___|__|__  | \__  / \/\_/  |__|
                                  \/          \/     \/

        watchTowr-vs-Fortiweb-AuthBypass.py

        (*) FortiWeb Authentication Bypass Artifact Generator

          - Sina Kheirkhah (@SinSinology) and Jake Knott (@inkmoro) of watchTowr (@watchTowrcyber)

        CVEs: [CVE-2025-xxxxx]

[+] Exploit sent successfully.
[*] Check for the new user [ 35f36895 ] with password [ 35f36895 ]


Description

This script attempts to detect if FortiWeb is vulnerable to Authentication Bypass

Affected Versions

FortiWeb Versions Below 8.0.2 are affected, for more specific versions please contact FortiGuard Labs PSIRT

Follow watchTowr Labs

For the latest security research follow the watchTowr Labs Team

  • https://labs.watchtowr.com/
  • https://x.com/watchtowrcyber
Download Tool