What happened
Fortinet FortiOS contains an out-of-bound write vulnerability that allows a remote unauthenticated attacker to execute code or commands via specially crafted HTTP requests.
Affected versions
FortiOS: See original advisory Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
PoC-in-GitHub · BishopFox/cve-2024-21762-checkSafely detect whether a FortiGate SSL VPN is vulnerable to CVE-2024-21762★ 107BishopFox2024-02-28CandidatePoC-in-GitHub · h4x0r-dz/CVE-2024-21762out-of-bounds write in Fortinet FortiOS CVE-2024-21762 vulnerability★ 150h4x0r-dz2024-03-13CandidatePoC-in-GitHub · r4p3c4/CVE-2024-21762-Exploit-PoC-Fortinet-SSL-VPN-CheckChequea si tu firewall es vulnerable a CVE-2024-21762 (RCE sin autenticación)★ 16r4p3c42024-03-13CandidatePoC-in-GitHub · d0rb/CVE-2024-21762The PoC demonstrates the potential for remote code execution by exploiting the identified security flaw.★ 12d0rb2024-03-17CandidatePoC-in-GitHub · rdoix/cve-2024-21762-checker★ 1rdoix2024-06-20CandidatePoC-in-GitHub · deFr0ggy/CVE-2024-21762-CheckerThis script performs vulnerability scanning for CVE-2024-21762, a Fortinet SSL VPN remote code execution vulnerability. It checks whether a given server is vulnerable to this CVE by sending specific requests and analyzing the responses.★ 0deFr0ggy2024-10-24CandidatePoC-in-GitHub · CrackerCat/cve-2024-21762-pocCVE-2024-21762 是 Fortinet 公司的 FortiOS 和 FortiProxy 产品中的一个严重漏洞,存在于其 SSL VPN 组件中。★ 0CrackerCat2025-04-03CandidatePoC-in-GitHub · abrewer251/CVE-2024-21762_FortiNet_PoCProof-of-concept scanner targeting CVE-2024-21762 in FortiOS SSL VPN’s /remote/hostcheck_validate endpoint with reverse shell payload delivery.★ 4abrewer2512025-05-22CandidatePoC-in-GitHub · 0x13-ByteZer0/CVE-2024-21762★ 00x13-ByteZer02026-01-13CandidatePoC-in-GitHub · 0x0asif/CVE-2024-21762★ 00x0asif2026-03-12CandidatePoC-in-GitHub · Sxmpl3/CVE-2024-21762-Safe-Check★ 0Sxmpl32026-06-24CandidatePoC-in-GitHub · Vampsecure-Labs/vamp-forticheckVampSecure Labs: FortiOS CVE scanner (CVE-2018-13379, CVE-2022-40684, CVE-2023-27997, CVE-2024-21762)★ 0Vampsecure-Labs2026-07-31CandidatePoC-in-GitHub · abraxas/Fortigate-SSL-VPN-Exploit-KitThe FortiGate SSL-VPN pot of gold. CVE-2024-21762 and CVE-2023-27997. 79 working exploit clients. 53 hardware SKUs. 55 FortiOS builds.★ 0abraxas2026-09-01CandidateSource timeline
Discovered through CISA Known Exploited VulnerabilitiesView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.