SERVER-WEBAPP -- Snort has detected traffic exploiting vulnerabilities in web based applications on servers.
SERVER-WEBAPP Fortinet FortiGate information disclosure attempt
This rule looks for a request URI that contains multiple consecutive slashes in the "/lang/custom" endpoint. Successful exploitation allows an unauthenticated attacker to read arbitrary files from the device.
This rule fires on attempts to exploit an information disclosure vulnerability in Fortinet FortiGate firewalls.
No public information
No known false positives
Cisco Talos Intelligence Group
Rule Categories::Server::Web Applications
MITRE::ATT&CK Framework::Enterprise::Initial Access::Exploit Public-Facing Application
Vulnerability::Severity::Critical
Vulnerability::Severity::High
Vulnerability::Severity::Medium
Information Leak
Information Leakage happens when an attacker manipulates a system into revealing sensitive information, either through malformed input or by taking advantage of another feature of the system.
CVE-2025-68686 |
Loading description
|