Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2025-25257 PoC — Fortinet FortiWeb SQL注入漏洞

Source
Associated Vulnerability
Title: Fortinet FortiWeb SQL注入漏洞 (CVE-2025-25257)
Description:An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.7, FortiWeb 7.2.0 through 7.2.10, FortiWeb 7.0.0 through 7.0.10 allows an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.
Readme
# CVE-2025-25257 - FortiWeb Vulnerability Checker & Exploit

A Python-based tool for checking and exploiting CVE-2025-25257 vulnerability in FortiWeb devices. This vulnerability allows SQL injection and remote code execution through a crafted Authorization header.


## 📋 Description

CVE-2025-25257 is a critical vulnerability in FortiWeb devices that allows:
- SQL injection via the Authorization header
- Remote code execution through webshell upload
- Unauthorized access to vulnerable systems

## 🚀 Features

- **Automated vulnerability detection** for single targets or bulk scanning
- **SQL injection exploitation** to upload webshells
- **Command execution** via uploaded webshell
- **Bulk target processing** from file input
- **Results logging** with timestamps
- **Comprehensive error handling**

## 📦 Requirements

```bash
pip install requests urllib3
```

## 🛠️ Installation

1. Clone the repository:
```bash
git clone https://github.com/yourusername/CVE-2025-25257.git
cd CVE-2025-25257
```

2. Install dependencies:
```bash
pip install -r requirements.txt
```

## 📖 Usage

### Vulnerability Checker (`vuln_check.py`)

Check a single target:
```bash
python3 vuln_check.py -t https://target.com
```

Check multiple targets from a file:
```bash
python3 vuln_check.py -l target.txt
```

### Command Execution (`exp.py`)

Execute commands on a vulnerable target:
```bash
python3 exp.py -t https://target.com -c "id"
```

## 📁 Files

- `vuln_check.py` - Main vulnerability checker and exploit
- `exp.py` - Command execution tool for vulnerable targets
- `target.txt` - Sample list of targets (replace with your own)
- `vuln.txt` - Output file with vulnerable targets (generated after scan)

## 🔍 How It Works

1. **SQL Injection**: Exploits the vulnerable API endpoint `/api/fabric/device/status`
2. **Webshell Upload**: Uses SQL injection to write a webshell to `/cgi-bin/x.cgi`
3. **Command Execution**: Executes commands via the uploaded webshell
4. **Verification**: Tests command execution to confirm successful exploitation

## 📊 Output

The tool generates a `vuln.txt` file containing:
- Timestamp of each scan
- Vulnerable target URLs
- Command execution results
- Scan statistics

Example output:
```
# CVE-2025-25257 Vulnerable Targets - 2025-01-27 10:30:15
# Format: [timestamp] target - command_output

[2025-01-27 10:30:15] https://target.com - uid=0(root) gid=0(root) groups=0(root)
```


---

**credit**:0xbigshaq
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →