Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1110 CNY

100%

CVE-2022-40684 PoC — Fortinet FortiOS 授权问题漏洞

Source
Associated Vulnerability
Title:Fortinet FortiOS 授权问题漏洞 (CVE-2022-40684)
Description:An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.
Description
Research repository tracking affected IPs from the Fortigate CVE-2022-40684 configuration leak by Belsen Group
Readme
    ╔═════════════════════════════════════════════════════════════════════════════╗
    ║   ███████╗ ██████╗ ██████╗ ████████╗██╗ ██████╗  █████╗ ████████╗███████╗   ║
    ║   ██╔════╝██╔═══██╗██╔══██╗╚══██╔══╝██║██╔════╝ ██╔══██╗╚══██╔══╝██╔════╝   ║
    ║   █████╗  ██║   ██║██████╔╝   ██║   ██║██║  ███╗███████║   ██║   █████╗     ║
    ║   ██╔══╝  ██║   ██║██╔══██╗   ██║   ██║██║   ██║██╔══██║   ██║   ██╔══╝     ║
    ║   ██║     ╚██████╔╝██║  ██║   ██║   ██║╚██████╔╝██║  ██║   ██║   ███████╗   ║
    ║   ╚═╝      ╚═════╝ ╚═╝  ╚═╝   ╚═╝   ╚═╝ ╚═════╝ ╚═╝  ╚═╝   ╚═╝   ╚══════╝   ║
    ║                                                                             ║
    ║      ██████╗ ███████╗██╗     ███████╗███████╗███╗   ██╗                     ║
    ║      ██╔══██╗██╔════╝██║     ██╔════╝██╔════╝████╗  ██║                     ║
    ║      ██████╔╝█████╗  ██║     ███████╗█████╗  ██╔██╗ ██║                     ║
    ║      ██╔══██╗██╔══╝  ██║     ╚════██║██╔══╝  ██║╚██╗██║                     ║
    ║      ██████╔╝███████╗███████╗███████║███████╗██║ ╚████║                     ║
    ║      ╚═════╝ ╚══════╝╚══════╝╚══════╝╚══════╝╚═╝  ╚═══╝                     ║
    ║                                                                             ║
    ║      ██╗     ███████╗ █████╗ ██╗  ██╗                                       ║
    ║      ██║     ██╔════╝██╔══██╗██║ ██╔╝                                       ║
    ║      ██║     █████╗  ███████║█████╔╝                                        ║
    ║      ██║     ██╔══╝  ██╔══██║██╔═██╗                                        ║
    ║      ███████╗███████╗██║  ██║██║  ██╗                                       ║
    ║      ╚══════╝╚══════╝╚═╝  ╚═╝╚═╝  ╚═╝                                       ║
    ║                                                                             ║
    ║                    Configuration Leak Tracker                               ║
    ╚═════════════════════════════════════════════════════════════════════════════╝

# Fortigate Belsen Leak Research

This repository contains informaion about the Fortigate firewall vulnerability (CVE-2022-40684) and affected IPs that were publicly disclosed by the Belsen Group. This information is being shared for security research and defensive purposes to help organizations identify if they were impacted.

## Background

In 2022, Fortinet disclosed a critical authentication bypass vulnerability (CVE-2022-40684) affecting FortiOS, FortiProxy, and FortiSwitchManager. In January 2025, configurations from approximately 15,000 affected devices were publicly released by the Belsen Group.

## Purpose

This repository serves as a resource for:
- Security researchers studying the impact of CVE-2022-40684
- Organizations to check if they were affected
- Raising awareness about the importance of timely security patches

## Contents

- `affected_ips.txt`: List of IP addresses identified as potentially affected
- `REFERENCES.md`: Additional resources and references about the vulnerability

## Disclaimer

This information is provided for defensive security research purposes only. The data has been publicly disclosed and is being shared to help organizations assess their exposure and take necessary remediation steps.

## References

- [Fortinet Advisory](https://www.fortinet.com/blog/psirt-blogs/update-regarding-cve-2022-40684)
- CVE-2022-40684

## Contact & Support

If your organization has been impacted by this vulnerability or you need assistance with mitigation:
- 💼 LinkedIn: [Amram Englander](https://www.linkedin.com/in/amram-englander-a23a6a89/)
- 📧 Secure Email: amrameng@proton.me
- 🛡️ For urgent security assistance or consultation, feel free to reach out via ProtonMail or LinkedIn

I'm available to help organizations:
- Verify if they were affected
- Provide guidance on mitigation steps
- Assist with security hardening
File Snapshot

[4.0K] /data/pocs/f6e87c5614af4291350006befad9d7de6c850678 ├── [299K] affected_ips.txt ├── [1.0K] LICENSE ├── [5.6K] README.md └── [1.1K] REFERENCES.md 0 directories, 4 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →