
Détecte le contournement d'authentification CVE-2025-64446 dans FortiWeb en exploitant une traversée de chemin pour confirmer la vulnérabilité, sans actions administratives.
Scanner de contournement d'authentification FortiWeb par Bishop Fox
Pour plus d'informations sur cette vulnérabilité, consultez le blog de Bishop Fox.
git clone https://github.com/BishopFox/fortiweb-auth-bypass-check
cd fortiweb-auth-bypass-check
python3 -m pip install requests
python3 scan.py https://[TARGET]
# Vulnerable target
$ python3 scan.py https://example1.com
[*] Testing https://example1.com
[!] Target is VULNERABLE - update immediately!
# Unaffected target
$ python3 scan.py https://example2.com
[*] Testing https://example2.com
[+] Target is not affected
# Invalid target
$ python3 scan.py https://example3.com
[*] Testing https://example3.com
[-] Target does not appear to be FortiWeb
Ce code est distribué sous licence MIT.