References https://avd.aliyun.com/detail?id=AVD-2022-40684 https://cve.imfht.com/detail/CVE-2022-40684 https://bbs.kanxue.com/thread-275335.htm https://zhuanlan.zhihu.com/p/575575181 https://xxhc.yzu.edu.cn/info/1096/9893.htm https://blog.csdn.net/d6e7f8g9h/article/details/154109966 https://www.ctfiot.com/70650.html https://nosec.org/m/share/5038.html https://www.ddpoc.com/DVB-2022-3997.html https://www.fortinet.com/blog/psirt-blogs/update-regarding-cve-2022-40684 https://www.fortiguard.com/psirt/FG-IR-22-377 https://nvd.nist.gov/vuln/detail/cve-2022-40684 https://horizon3.ai/attack-research/attack-blogs/fortios-fortiproxy-and-fortiswitchmanager-authentication-bypass-technical-deep-dive-cve-2022-40684/ https://github.com/horizon3ai/CVE-2022-40684 https://www.sentinelone.com/vulnerability-database/cve-2022-40684/ https://www.picussecurity.com/resource/blog/cve-2022-40684-fortinet-authentication-bypass-vulnerability-explained https://www.rapid7.com/blog/post/2022/10/07/cve-2022-40684-remote-authentication-bypass-vulnerability-in-fortinet-firewalls-web-proxies/ https://research.splunk.com/web/a83122f2-fa09-4868-a230-544dbc54bc1c/ https://www.reddit.com/r/fortinet/comments/xy098w/fortigate_web_management_vulnerability/
Related VulnerabilitiesPoCCVE-2026-39808: Fortinet FortiSandbox - Command InjectionFortinet FortiSandbox /fortisandbox/job-detail/tracer-behavior 命令执行漏洞(CVE-2026-39808)PoCCVE-2026-21643: Fortinet FortiClientEMS 7.4.4 - SQL InjectionPoCCVE-2019-5591: FortiOS - Insecure LDAP Configuration DetectionPoCCVE-2025-52970: Fortinet FortiWeb - Authentication Bypass to Admin PrivilegeFortinet FortiOS等 签名验证不当漏洞Fortinet FortiWeb /api/v2.0/cmdb/system/admin%3f/../../../../../cgi-bin/fwbcgi 权限绕过漏洞(CVE-2025-64446/CVE-2025-58034)Fortinet FortiWeb 需授权 命令注入漏洞Fortinet FortiWeb /api/v2.0/cmdb/system/admin%3f/../../../../../cgi-bin/fwbcgi 权限绕过漏洞(CVE-2025-64446)