module

Fortinet FortiWeb create new local admin

Disclosed
Nov 14, 2025
Created
Nov 14, 2025

Description

This auxiliary module exploits an authentication bypass via path traversal vulnerability in the Fortinet
FortiWeb management interface to create a new local administrator user account. This vulnerability affects the
following versions:

* FortiWeb 8.0.0 through 8.0.1 (Patched in 8.0.2 and above)
* FortiWeb 7.6.0 through 7.6.4 (Patched in 7.6.5 and above)
* FortiWeb 7.4.0 through 7.4.9 (Patched in 7.4.10 and above)
* FortiWeb 7.2.0 through 7.2.11 (Patched in 7.2.12 and above)
* FortiWeb 7.0.0 through 7.0.11 (Patched in 7.0.12 and above)

Authors

Defused
sfewer-r7

Module Options

To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':


msf > use auxiliary/admin/http/fortinet_fortiweb_create_admin
msf auxiliary(fortinet_fortiweb_create_admin) > show actions
...actions...
msf auxiliary(fortinet_fortiweb_create_admin) > set ACTION < action-name >
msf auxiliary(fortinet_fortiweb_create_admin) > show options
...show and set options...
msf auxiliary(fortinet_fortiweb_create_admin) > run

Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.