Rule Category

SERVER-WEBAPP -- Snort has detected traffic exploiting vulnerabilities in web based applications on servers.

Alert Message

SERVER-WEBAPP Fortinet FortiGate information disclosure attempt

Rule Explanation

This rule looks for a request URI that contains multiple consecutive slashes in the "/lang/custom" endpoint. Successful exploitation allows an unauthenticated attacker to read arbitrary files from the device.

What To Look For

This rule fires on attempts to exploit an information disclosure vulnerability in Fortinet FortiGate firewalls.

Known Usage

No public information

False Positives

No known false positives

Contributors

Cisco Talos Intelligence Group

Rule Groups

Rule Categories::Server::Web Applications

MITRE::ATT&CK Framework::Enterprise::Initial Access::Exploit Public-Facing Application

Vulnerability::Severity::Critical

Vulnerability::Severity::High

Vulnerability::Severity::Medium

CVE

Rule Vulnerability

Information Leak

Information Leakage happens when an attacker manipulates a system into revealing sensitive information, either through malformed input or by taking advantage of another feature of the system.

CVE Additional Information

This product uses data from the NVD API but is not endorsed or certified by the NVD.
CVE-2025-68686
Loading description