Skip to content

A Threat Actor is Allegedly Selling RCE Exploits for Fortinet SSL VPN

The forum link can be found at the bottom of this post. If you are not a paid subscriber, you will not see it!

The post reads:


Price: 10,000

Contacts: P.M

Post Content:

Hi,

I started to sell 2 RCE of Fortinet SSLVPN full exploit chain for all devices.

Based on this topic: [link removed]. I speak about the difference between released POCs and Full Exploit Chain.

The ZIP file consists of:

  • 4 Python codes (for each CVE, 4 files for 2 different architectures provided in Fortinet)
  • A text file (or if you want, I can convert it to JSON file) with gadgets needed and addresses (for x86 and ARM32). If you need AARCH64, some additional fee is needed.
  • 1 Python file as a shellcode generator (that can use with 2 CVEs as payload)
  • 1 Python file for version detection based on CVE-2024-23662
  • A tutorial file for using and a sample silver agent payload that is used for testing.

If you need, feel free to contact me.

Have a nice day.

This post is for paying subscribers only

Subscribe

Already have an account? Sign In

Latest