ZeroHour
SOCRadarpublished ()ingested ameer

CVE-2025-25249 Exploitation Delivers PivotC2, a FortiGate Post-Exploitation RAT

highExploit / PoC exploited in the wildimportance 74CVE-2025-25249
AI summary · glm-5.3-flash

Attackers exploiting CVE-2025-25249 in Fortinet FortiGate firewalls deploy PivotC2, a post-exploitation RAT, on exposed edge devices.

SOCRadar reports that exploitation of CVE-2025-25249 is being used to deploy PivotC2, a purpose-built post-exploitation RAT, on FortiGate firewall appliances. The attack follows the common pattern of compromising public-facing edge devices such as VPNs, routers, and firewalls as the initial entry point. Defenders running FortiGate appliances should prioritize patching and watch for post-exploitation activity indicating RAT deployment.

  • CVE-2025-25249 exploitation on FortiGate delivers the PivotC2 post-exploitation RAT
  • Public-facing edge devices like VPNs, routers, and firewalls are common initial entry points
  • FortiGate operators should patch and monitor for post-exploitation indicators
ProductsFortiGate
MalwarePivotC2

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-25249
Heap-Based Buffer Overflow in Fortinet FortiOS, FortiSwitchManager, and FortiSASE

CVE-2025-25249 is a heap-based buffer overflow (CWE-122/CWE-787) in Fortinet FortiOS, FortiSwitchManager, and FortiSASE that allows an attacker to execute unauthorized code or commands. It is triggered by sending specially crafted packets to an affected device, causing an out-of-bounds write in heap memory that can be leveraged for code execution. Successful exploitation gives attackers command execution on the appliance; in observed intrusions against FortiGate firewalls, attackers have deployed custom Node.js malware and a post-exploitation RAT dubbed PivotC2. Any organization running the affected Fortinet products is at risk, with internet-facing FortiGate firewalls the primary concern. The flaw was added to CISA's KEV on 2026-09-09, confirming active exploitation in the wild (ransomware use unknown); no public PoC is known.

Do: Upgrade FortiOS, FortiSwitchManager, and FortiSASE in accordance with Fortinet's advisory (specific fixed versions are not listed in the available data), prioritizing internet-exposed FortiGate firewalls per CISA KEV and BOD 26-04 timelines. Hunt for signs of compromise, including custom Node.js malware and the PivotC2 RAT, on FortiGate devices, and review exposure and access logs for admin/SSL-VPN interfaces. If patching is not possible, apply vendor-recommended mitigations or, per BOD 26-04, discontinue use of the exposed product.

9.82% KEV PoC
  • Fortinet FortiOS
  • Fortinet FortiSwitchManager
  • Fortinet FortiSASE
mass≈300,000–500,000 internet-exposed FortiGate/FortiOS devices (plus FortiSASE cloud tenants)
Full article

CVE-2025-25249 Exploitation Delivers PivotC2, a FortiGate Post-Exploitation RAT One of the most common entry points for attackers is the exploitation of public-facing edge devices (such as VPNs, routers, and firewalls).

The full text could not be extracted from this site (paywall, bot protection or heavy scripting). Read it at socradar.io.