Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2024-55591 PoC — Fortinet FortiOS和FortiProxy 安全漏洞

Source
Associated Vulnerability
Title: Fortinet FortiOS和FortiProxy 安全漏洞 (CVE-2024-55591)
Description:An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.
Readme

# CVE-2024-55591: FortiOS Authentication Bypass  

**If you’re reading this, you most likely know what we’re talking about.**

![CVE](https://img.shields.io/badge/CVE-2024--55591-critical)  
![Python](https://img.shields.io/badge/Python-3.8%2B-blue)  
![License](https://img.shields.io/badge/License-MIT-green)  




## *[Download](https://satoshidisk.com/pay/CO99uu) - JUST TAKE IT*

---
# Detection in Action

```
python3 binarywarm-exp.py --host 192.104.119.11 --port 443 --command "show user local" --ssl



                      ██████╗ ██╗███╗   ██╗ █████╗ ██████╗ ██╗   ██╗    ██╗    ██╗ █████╗ ██████╗ ███╗   ███╗
                      ██╔══██╗██║████╗  ██║██╔══██╗██╔══██╗╚██╗ ██╔╝    ██║    ██║██╔══██╗██╔══██╗████╗ ████║
                      ██████╔╝██║██╔██╗ ██║███████║██████╔╝ ╚████╔╝     ██║ █╗ ██║███████║██████╔╝██╔████╔██║
                      ██╔══██╗██║██║╚██╗██║██╔══██║██╔══██╗  ╚██╔╝      ██║███╗██║██╔══██║██╔══██╗██║╚██╔╝██║
                      ██████╔╝██║██║ ╚████║██║  ██║██║  ██║   ██║       ╚███╔███╔╝██║  ██║██║  ██║██║ ╚═╝ ██║
                      ╚═════╝ ╚═╝╚═╝  ╚═══╝╚═╝  ╚═╝╚═╝  ╚═╝   ╚═╝        ╚══╝╚══╝ ╚═╝  ╚═╝╚═╝  ╚═╝╚═╝     ╚═╝
                          



            binarywarm-exp.py
            (*) Fortinet FortiOS Authentication Bypass (CVE-2024-55591) POC by binarywarm
        
            CVEs: [CVE-2024-55591]

            [*] Checking if target is a FortiOS Management interface
            [*] Target is confirmed as a FortiOS Management interface
            [*] Target is confirmed as vulnerable to CVE-2024-55591, proceeding with exploitation
            Output from server: �m"watchTowr" "admin" "watchTowr" "super_admin" "watchTowr" "watchTowr" [13.37.13.37]:1337 [13.37.13.37]:1337

            Output from server: �
            get system status

            Output from server: �~�FAKESERIAL # "Local_Process_Access" "Local_Process_Access" "root" "" "" "none" [x.x.x.x]:54546 [x.x.x.x]:443
            Unknown action 0

            FAKESERIAL # 
            FAKESERIAL # get system status
            Version: FortiGate-VM64-AWS v7.0.16,build0667,241001 (GA.M)
            Security Level: High
            Firmware Signature: certified
            Virus-DB: 1.00000(2018-04-09 18:07)
```
---

#  Description  
A critical authentication bypass vulnerability in FortiOS (versions 7.4.0-7.4.2 and 7.2.0-7.2.6) allows unauthorized administrative access through WebSocket protocol manipulation. This repository contains two tools:
1. **Exploit (exp.py)** - Proof-of-Concept for vulnerability exploitation
2. **Scanner (scanner-cve2024-55591.py)** - Mass detection tool with Telegram notifications

---

#  Technical Details  
**Vulnerability Type**: Session Hijacking via WebSocket Negotiation  
**Attack Vector**:  
- WebSocket handshake manipulation with forged headers  
- Invalid session token acceptance  
- Privileged CLI command execution

#  Pentest Environment Setup in `scrypt` Directory

## 1. Initial Server Configuration

### Update system and install core tools
```
sudo apt update && sudo apt full-upgrade -y
sudo apt install -y git python3.10-venv python3-pip python3-dev build-essential libssl-dev libffi-dev ca-certificates
```
**Affected Components**:  
- `/ws/cli/open` WebSocket endpoint  
- Service Worker API (`/service-worker.js`)

## 2. Install base dependencies
```
sudo apt install -y python3 python3-venv python3-pip git
```
## 3. Create project directory and navigate to it
```
mkdir /scrypt && cd /scrypt
```
## 4. Create Python virtual environment named "pentest"
```
python3 -m venv pentest
```
## 5.  Activate virtual environment
```
source pentest/bin/activate
```
## 6. Install required Python packages
```
pip install requests urllib3 python-telegram-bot
```
## 7. Move the files exp.py, scanner.py, and targets.txt to the /scrypt directory
---
---
# Vulnerability searching

 ## Description
 The script cve2032copy2.py scans a list of Fortinet addresses (listed line-by-line in a text file) for the reported vulnerability 
 and sends positive detection results to your Telegram bot.
 
 ## Start scanner
 ```
 python3 scanner-cve2024-55591.py --file targets.txt --port 443

 ```









File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →