CVE-2022-42475 is a critical heap-based buffer overflow in the sslvpnd component of FortiOS and FortiProxy SSL-VPN. Specially crafted requests can corrupt heap memory and permit a remote unauthenticated attacker to execute arbitrary code or commands. Affected releases include FortiOS 7.2.0–7.2.2, 7.0.0–7.0.8, 6.4.0–6.4.10, 6.2.0–6.2.11, and 6.0.15 and earlier; FortiProxy 7.2.0–7.2.1, 7.0.0–7.0.7, 2.0.0–2.0.11, and earlier supported branches are also affected. Fortinet confirmed exploitation in the wild.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
6 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Go proof-of-concept exploit for CVE-2022-42475, a pre-authentication heap-based buffer overflow in Fortinet FortiOS SSL VPN. The repository contains only two files: a README describing the vulnerability, affected versions, and usage, and a single Go source file implementing the exploit logic. The main exploit file, CVE-2022-42475.go, accepts a target host, target port, attacker callback IP, and shell arguments. It builds a malicious HTTPS POST request to the FortiOS SSL VPN endpoint /remote/error with an extremely large Content-Length and a large overflow buffer. The payload includes hardcoded ROP gadget addresses and a hardcoded base address, indicating the exploit is tailored to a specific target memory layout rather than broadly reliable across all builds. The ROP chain is designed to call execve and launch /bin/python on the target. It passes a Python payload that connects back to the attacker on TCP port 80, duplicates the socket onto stdin/stdout/stderr, forks, and executes /bin/sh with attacker-provided arguments such as /bin/sh -i. The exploit uses a raw TCP connection upgraded to TLS with certificate verification disabled, performs a handshake, sends headers and payload, then closes the write side immediately in a fire-and-forget manner. It optionally attempts to read a short response afterward. Operationally, the exploit provides unauthenticated remote code execution with a reverse shell if the target is vulnerable and the hardcoded addresses are correct. The code itself warns that the target may crash and that the base address may need brute forcing, so this is better characterized as an operational PoC than a polished weaponized exploit. Fingerprintable artifacts include the /remote/error endpoint, the TLS connection to the target SSL VPN port, the reverse callback to attacker IP:80, and the use of /bin/python and /bin/sh on the target.
Repository contains a Python exploit for CVE-2022-42475 (Fortinet FortiGate/FortiOS SSL-VPN pre-auth RCE) plus helper code and assembly shellcode. The main entry point is CVE-2022-42475.py, which builds a malicious HTTP request leveraging a Content-Length integer overflow (default set to 2^32+1) to trigger memory corruption in the SSL-VPN daemon (sslvpnd). It supports: (1) validate-only mode that attempts to crash/restart the service and heuristically reports vulnerability; (2) a simple callback mode that executes minimal shellcode which connects back and sends a marker string; and (3) a full exploit mode that uses a ROP chain to call functions like mprotect/calloc and AES routines, then runs shellcode that stages an AES-encrypted operator-supplied binary, writes it to /tmp/x, and execve()s it. The exploit can optionally route traffic through a local Burp proxy (127.0.0.1:8080) using an HTTP CONNECT tunnel. TLS is auto-enabled for common HTTPS ports (443/8443/10443) unless overridden. The ROP construction logic is encapsulated in foxrop.py (class ROP), which imports gadget/function addresses from an external JSON file (referenced in README as exploit_data.json). This repository is explicitly a redacted release: without the proprietary gadget/address data, full RCE is not directly usable across targets, though the structure clearly implements a real exploitation chain. Included shellcode sources: shellcode.s implements the full connect-back stager (socket/connect, hello byte exchange, receive size + encrypted payload, AES-CBC decrypt using imported function pointers, write to /tmp/x, then execve). shellcode_callback.s is a minimal proof-of-execution payload that connects back and writes a model/marker string (e.g., 'PWNED'). requirements.txt pins pycryptodome for AES operations used by the Python-side payload encryption and coordination.
This repository contains a proof-of-concept exploit for CVE-2022-42475, a heap overflow vulnerability in Fortinet's SSLVPN daemon. The main file, cve-2022-42475.py, is a Python script that constructs a ROP chain to exploit the vulnerability and achieve remote code execution. The exploit works by sending a specially crafted HTTP POST request to the /remote/error endpoint of the target Fortinet device over SSL. The payload triggers the heap overflow and executes a reverse shell, connecting back to the attacker's machine on port 31337. The attacker can specify arbitrary commands to be executed on the target. The repository is structured simply, with a README providing usage instructions and a single exploit script. The exploit requires the attacker to set up a listener to receive the reverse shell. No detection or scanning functionality is present; this is a direct exploit script.
This repository contains a proof-of-concept (POC) exploit for CVE-2022-42475, a heap overflow vulnerability in Fortinet's SSLVPN daemon (FortiOS). The main file, 'cve-2022-42475.py', is a Python script that constructs a ROP chain to execute a reverse shell payload on the target system. The exploit connects to the target's SSLVPN service over SSL, sends a specially crafted HTTP POST request to the '/remote/error' endpoint with a large payload designed to trigger the heap overflow, and attempts to execute a reverse shell back to the attacker's machine on port 31337. The payload uses /bin/python to create a socket and spawn /bin/sh, passing attacker-supplied arguments. The exploit is version dependent, with hardcoded offsets and addresses that may require adjustment for different target systems. The repository also includes a README.md that describes the exploit's limitations and version dependency. No detection scripts or fake code are present; this is a real exploit POC targeting a specific vulnerability in Fortinet FortiOS.
This repository contains a working exploit for CVE-2022-42475, a pre-authentication remote code execution vulnerability in Fortinet FortiOS SSL VPN. The main exploit script (CVE-2022-42475.py) is a Python3 tool that can operate in several modes: vulnerability validation (crash detection), benign connect-back shellcode execution, and full payload delivery (implant deployment). The exploit leverages a buffer overflow in the SSL VPN webserver, using a custom ROP chain (constructed via foxrop.py and a required gadgets JSON file) to execute custom shellcode (provided in shellcode.s). The shellcode connects back to the attacker's machine, receives an encrypted payload (such as a Sliver implant), writes it to /tmp/x, and executes it. The exploit is operational but requires the operator to supply valid ROP gadget addresses for the target FortiOS version and hardware model. The README provides detailed usage instructions, requirements, and example output. The exploit targets FortiOS 6.0.4 on 100D hardware for full functionality, but the validation mode works across more versions. The main attack vector is network-based, targeting the SSL VPN web interface via a crafted HTTP POST request to /remote/logincheck. The repository includes Python code, an assembly shellcode file, and a requirements.txt for dependencies.
This repository contains a proof-of-concept exploit for CVE-2022-42475, a heap buffer overflow vulnerability in Fortinet's FortiOS SSL-VPN daemon. The main exploit script, 'cve-2022-42475.py', is a Python script that constructs a ROP chain to execute a reverse shell payload. The exploit targets the '/remote/error' endpoint of the SSLVPN service over SSL, sending a specially crafted POST request with a large payload to trigger the vulnerability. The payload includes hardcoded memory offsets and gadgets, making it highly version dependent and likely requiring adjustment for different target systems. Upon successful exploitation, the script establishes a reverse shell from the target to the attacker's machine on port 31337, executing a user-supplied command. The repository also includes a README with usage instructions and a disclaimer. No detection scripts or fake code are present; this is a functional exploit with operational-level maturity.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
60 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Fortinet FortiGate vulnerability probed as part of reconnaissance against 3BB's FortiGate SSL-VPN endpoint.
A FortiOS SSL-VPN heap-overflow vulnerability which the actor's reconnaissance script probed as a possible exploitation path.
An exploited FortiOS SSL-VPN vulnerability referenced as one of the flaws bypassed by CVE-2025-68686.
A Fortinet FortiOS SSL-VPN vulnerability used by the attackers as an initial access vector against internet-facing security appliances.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.