GITHUB-adminlove520/CVE-Poc_All_in_One/2025/CVE-2025-25252

GITHUB python WORKING POC
Exploit for CVE-2025-25252 - FortiOS SSL VPN <7.6.2, 7.4.6, 7.2.10, 7.0.16, 6.4 - Info Disclosure
AI Analysis

The repository contains a functional exploit for CVE-2025-25257, targeting FortiWeb's unauthenticated SQL injection vulnerability leading to remote code execution. The script constructs a malicious payload via chunked SQL queries to write a reverse shell to a file, demonstrating the vulnerability's exploitability.

Attack Type
RCE
Complexity
moderate
Reliability
reliable
MITRE ATT&CK
T1190 - Exploit Public-Facing Application T1059 - Command and Scripting Interpreter T1203 - Exploitation for Client Execution
Loading exploit code...
Download ZIP Password: eip
Source
Platform Github
Type poc
Language python
Files 2
Stars 2
Forks 0
Last Push Feb 17, 2026
Vulnerability
CVE-2025-25252
FortiOS SSL VPN <7.6.2, 7.4.6, 7.2.10, 7.0.16, 6.4 - Info Disclosure
MEDIUM
CVSS 4.8