• Home
  • Solutions
  • Courses
  • Patreon
  • Resources
    • Articles
    • InfoSec News
    • Premium Articles
    • Hacking Tools
  • Merch
  • About us
  • Contact us

EXTERNAL PENTESTING REAL WORLD WRITE UPS BY BHEH

External Pentesting Write ups

Internal Pentesting Write ups

OS Command Injection via ‘lang’ Parameter in Fortinet VPN SSL Interface

OS Command Injection via ‘lang’ Parameter in Fortinet VPN SSL Interface

Sep 2, 2025 | Articles, External Pentesting Write ups

During an external pentesting, a critical OS Command Injection vulnerability was identified by our team in a Fortinet SSL VPN web interface, specifically through manipulation of the lang (language) parameter.

read more
Critical FortiGate 100F SSL-VPN Vulnerability Exploited

Critical FortiGate 100F SSL-VPN Vulnerability Exploited

Jun 24, 2025 | Articles, External Pentesting Write ups

During an external pentesting, our red team identified a critical vulnerability on FortiGate 100F firewall appliances. The issue is CVE-2022-42475 – a heap-based buffer overflow in FortiOS’s SSL-VPN service that allows remote, unauthenticated code execution.

read more

ABOUT US

  • Press Release
  • Sponsorship-Advertising
  • Site Map
  • Terms of Services
  • Privacy & Policy

SOLUTIONS

  • Vulnerability Assessment
  • Penetration Testing
  • Digital Forensics
  • Social Engineering
  • Compliance Programs

SUPPORT

  • Submit a Ticket
  • Report an Incident
  • Vulnerability Disclosure Policy
  • Contact us

EDUCATION

  • Courses – Login
  • Premium Articles – Login
  • Patreon – Hacking Episodes
  • Offensive Security Courses
  • Security Awareness
  • Courses – Login
  • Premium Articles – Login
  • Patreon – Hacking Episodes
  • Offensive Security Courses
  • Security Awareness
  • Facebook
  • X
  • Instagram
  • RSS
© Copyright 2025 • Black Hat Ethical Hacking • All rights reserved