Home / os / winme

Fortinet FortiOS / FortiProxy / FortiSwitchManager Authentication Bypass

Posted on 19 October 2022

This Metasploit module exploits an authentication bypass vulnerability in the Fortinet FortiOS, FortiProxy, and FortiSwitchManager API to gain access to a chosen account and then adds an SSH key to the authorized_keys file of the chosen account, allowing you to login to the system with the chosen account. Successful exploitation results in remote code execution.

 

TOP