
Rileva il bypass dell'autenticazione CVE-2025-64446 in FortiWeb sfruttando un path traversal per confermare la vulnerabilità, senza azioni amministrative.
Scanner per il bypass di autenticazione FortiWeb di Bishop Fox
Per maggiori informazioni su questa vulnerabilità, fare riferimento al blog di Bishop Fox.
git clone https://github.com/BishopFox/fortiweb-auth-bypass-check
cd fortiweb-auth-bypass-check
python3 -m pip install requests
python3 scan.py https://[TARGET]
# Vulnerable target
$ python3 scan.py https://example1.com
[*] Testing https://example1.com
[!] Target is VULNERABLE - update immediately!
# Unaffected target
$ python3 scan.py https://example2.com
[*] Testing https://example2.com
[+] Target is not affected
# Invalid target
$ python3 scan.py https://example3.com
[*] Testing https://example3.com
[-] Target does not appear to be FortiWeb
Questo codice è distribuito sotto una licenza MIT.