CVE-2025-52970 - FortiWeb Authentication Bypass to Remote Code Execution Exploit
-
Updated
Sep 7, 2025 - Python
CVE-2025-52970 - FortiWeb Authentication Bypass to Remote Code Execution Exploit
Deploy FortiWeb HA on Amazon AWS and Microsoft Azure
Scripts and guides to bring up Fortinet demos on Kubernetes
FortiWeb is a web application firewall (WAF)
CVE‑2025‑25257 is a critical pre-authentication SQL injection vulnerability affecting Fortinet FortiWeb’s
Push certificate on FortiWeb appliance using dehydrated
Client for FortiWeb in Go language using REST API
A powerful and modular PoC tool for CVE‑2025‑25257 in Fortinet FortiWeb, enabling reverse shell, encrypted data exfiltration, persistence, and cleanup capabilities.
🔍 Generate detection artifacts for FortiWeb authentication bypass vulnerabilities with this Python script to enhance your security testing.
Add a description, image, and links to the fortiweb topic page so that developers can more easily learn about it.
To associate your repository with the fortiweb topic, visit your repo's landing page and select "manage topics."