An external control of file name or path vulnerability [CWE-73] in FortiNAC webserver may allow an unauthenticated attacker to perform arbitrary write on the system.
🔖PoC exploit here
Usage:
python3 CVE-2022-39952.py --target IP --file payload
P. P.F.K Security @pfksecurity · 2.1K subscribers Forwarded from Private Shizo
CVE-2022-39952_PoC.zip2 KBpython3 CVE-2022-39952.py --target IP --file payload