Skip to content
KitploitKITPLOIT
工具博客
Log in
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
工具/GitHubGitHub/moften/cve-2025-59718-fortinet-poc
侦察漏洞扫描器漏洞利用信息收集网络安全渗透测试
GitHubmoften/cve-2025-59718-fortinet-poc

CVE-2025-59718-Fortinet-Poc

用于确定 Fortinet 是否易受 CVE-2025-59718 / CVE-2025-59719 漏洞影响的 PoC

查看仓库
3139个月前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

CVEs: CVE-2025-59718 / CVE-2025-59719 Fortinet Poc

用于检测 Fortinet(FortiOS / FortiGate)设备中与 CVE-2025-59718 和 CVE-2025-59719 相关漏洞的工具,通过多种识别技术实现:被动、主动和认证方式。

支持: • 通过指纹识别进行被动检测 • 主动验证(非破坏性) • 通过 SSH 进行认证连接 • 按文件批量扫描 • 导出结构化结果(JSON)


用法

最可靠的验证方式(含主动测试)⭐ 推荐

python3 main.py --mode passive --target firewall.company.com --active-test

SSH 模式(更可靠)

python3 main.py --mode ssh --target 192.168.1.1 --user admin --password 'MyPass123'

使用文件批量扫描多个目标

python3 main.py --mode ssh --targets targets.txt --user admin --keyfile ~/.ssh/fw_key

被动模式(无需凭据)

python3 main.py --mode passive --target https://firewall.company.com

将结果保存为 JSON

python3 main.py --mode passive --targets ips.txt --json results.json

静默扫描(仅 JSON)

python3 main.py --mode passive --target firewall.company.com --json out.json --quiet

带主动测试的批量扫描

python3 main.py --mode passive --targets ips.txt --active-test --json results.json

🎨 输出示例:

[*] [1/3] Escaneando 192.168.1.1...
[*] Conectando vía SSH a 192.168.1.1:22...

======================================================================
Target: 192.168.1.1
Mode: ssh
Verdict: [!!!] VULNERABLE - EXISTS
Confidence: high
Product: FortiOS
Version: 7.4.5
Patch Version: 7.4.9 or higher
FortiCloud SSO: ENABLED

Indicators:
  • Producto detectado: FortiOS v7.4.5
  • ⚠️  Versión 7.4.5 está en rango VULNERABLE
  • ⚠️  FortiCloud SSO login está HABILITADO

Notes:
  • Actualizar a versión 7.4.9 o superior
  • 🚨 CRÍTICO: Sistema VULNERABLE y FortiCloud SSO HABILITADO
  • 🚨 Este sistema está siendo explotado activamente in-the-wild
  • 🚨 ACCIÓN INMEDIATA REQUERIDA
======================================================================

🙌 请我喝杯咖啡?

如果你觉得这个工具有用,或者想支持未来的开发,可以请我喝杯咖啡 ☕ 或进行捐赠。任何支持都很重要!

Donate with PayPal


📬 联系与社交

  • 💌 邮箱:[email protected]
  • 🌐 博客:https://m10.com.mx
  • 🐦 Twitter:@hack4lifemx
  • 💼 LinkedIn:Francisco Santibañez
  • 🐙 GitHub:github.com/m10sec

🛡️ 理念

我相信一个用户能够掌控自己隐私的世界。这个工具诞生于真实的渗透测试前线,源于对数字自由和具有目标的黑客行为的热爱。


⭐ 如果你喜欢这个项目,请在 GitHub 上给它一个 star,并与你的社区分享。

下载工具