CVE-2018-13379: Fortinet FortiOS SSL VPN path traversal

HoneyLabs honeypots recorded 13 probes matching CVE-2018-13379 from 6 distinct source IP addresses in the last 7 days. Severity is rated critical.

This CVE is on CISA's Known Exploited Vulnerabilities list.

Request paths that identify it

  • /remote/fgt_lang
  • /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession

Addresses probing it

Source IPProbesNetworkCountry
5.188.206.2028Krez 999 EoodBulgaria
45.56.72.1421Akamai Connected CloudUnited States
45.79.2.1831Akamai Connected CloudUnited States
143.244.148.1321DigitalOcean, LLCUnited States
45.79.218.2441Akamai Connected CloudUnited States
96.126.108.1461Akamai Connected CloudUnited States

Networks it comes from

ASNOrganisationProbesSource IPs
AS200391Krez 999 Eood81
AS63949Akamai Connected Cloud44
AS14061DigitalOcean, LLC11

Captured requests

  • /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession

HTTP client fingerprints (JA4H)

  • ge11nn0400_8fd06a127c33
  • ge11nn0300_dedeb29cc523

CVE report

CVE report

Open a specific CVE from the CVE tracker.