Fortinet CVE-2025-25249 Exploited to Deploy PivotC2 Node.js RAT on FortiGate Firewalls; CISA Adds Flaw to KEV With September 12 Federal Deadline
Threat actors are actively exploiting CVE-2025-25249, a heap-based buffer overflow in the FortiOS/FortiSwitchManager cw_acd daemon reachable via CAPWAP on UDP 5246, to deploy the PivotC2 Node.js RAT — compromising at least 178 of 30,000+ scanned FortiGate…
SOCRadar's Threat Research Unit, as relayed by Cyber Security News, GBHackers and SecurityWeek, reports active exploitation of CVE-2025-25249, an unauthenticated remote code execution heap-based buffer overflow (classified as CWE-122/CWE-787 by CISA, per Cyber Security News) in the cw_acd daemon of FortiOS and FortiSwitchManager, triggered via specially crafted CAPWAP packets to UDP port 5246. Sources disagree on severity: Cyber Security News and GBHackers (citing SOCRadar) rate it CVSS 9.8, while SecurityWeek cites CVSS 7.4. Per Cyber Security News, affected versions include FortiOS 6.4 through 7.6.3 and FortiSwitchManager 7.0.x/7.2.x; SecurityWeek says the flaw was patched in January, which the Canadian Centre for Cyber Security ties to Fortinet's January 2026 advisories spanning FortiFone, FortiOS, FortiSASE, FortiSIEM and FortiSwitchManager. Since July 2026, attackers scanned more than 30,000 internet-exposed FortiGate IP addresses and compromised at least 178 devices, dropping fortirun.bin and PivotC2, a Node.js post-exploitation RAT providing interactive shells, SOCKS5/HTTP proxying, port forwarding, network scanning and automated configuration harvesting. PivotC2 decrypts stored credentials from fsv_sync.dat — VPN pre-shared keys, SSL-VPN credentials, LDAP secrets, and wireless and admin credentials — using AES-256-CBC and AES-128-GCM. SOCRadar attributes the campaign with high confidence to a Russian-speaking, financially motivated cybercrime operator, citing Russian-language artifacts, AD enumeration, browser credential theft, RDP enablement and suspected AI-assisted tooling. Two US organizations suffered confirmed full-network intrusions with Exchange mailbox/.pst exfiltration to Wasabi S3 storage; per GBHackers, the US is the most affected country, followed by Chile, Colombia and the UK. On September 9, 2026, CISA added CVE-2025-25249 to its Known Exploited Vulnerabilities catalog, a move relayed in the Canadian Centre for Cyber Security's advisory AV26-023 Update 1. Federal agencies face a September 12, 2026 remediation deadline under BOD 26-04 — described by SecurityWeek as a three-day deadline — and CISA requires mandatory forensic triage of affected environments rather than routine patching alone; ransomware use is currently listed as unknown, and internet-facing FortiOS, FortiSwitchManager and FortiSASE assets are flagged as a likely foothold. The Canadian advisory also flags related Fortinet flaws: CVE-2025-47855 (unauthenticated local…
- CVE-2025-25249 is an unauthenticated heap-based buffer overflow (CWE-122/CWE-787) in the FortiOS/FortiSwitchManager cw_acd daemon, exploited via crafted CAPWAP packets to UDP 5246; severity is disputed — CVSS 9.8 per Cyber Security…
- Affected versions per Cyber Security News: FortiOS 6.4 through 7.6.3 and FortiSwitchManager 7.0.x/7.2.x; SecurityWeek says the flaw was patched in January (tied by the Canadian Centre to Fortinet's January 2026 advisories).
- Since July 2026, attackers scanned over 30,000 internet-exposed FortiGate IPs and compromised at least 178 devices, deploying fortirun.bin and the PivotC2 Node.js RAT.
- PivotC2 provides interactive shells, SOCKS5/HTTP proxying, port forwarding and network scanning, and decrypts fsv_sync.dat credentials (VPN pre-shared keys, SSL-VPN, LDAP secrets, wireless/admin) using AES-256-CBC and AES-128-GCM.
- Two US organizations confirmed full-network intrusions with Exchange mailbox/.pst exfiltration to Wasabi S3; most affected countries per GBHackers: US, then Chile, Colombia and the UK.
- SOCRadar attributes the campaign with high confidence to a Russian-speaking, financially motivated cybercrime operator; AI-assisted tooling is suspected.
- CISA added CVE-2025-25249 to the KEV catalog on September 9, 2026 (relayed in Canadian Centre advisory AV26-023 Update 1); federal remediation deadline September 12, 2026 under BOD 26-04, with mandatory forensic triage; ransomware use…
- Patches: FortiOS 7.6.4/7.4.9/7.2.12/7.0.18 and FortiSwitchManager 7.2.7/7.0.6; mitigations include blocking UDP 5246–5249, hunting for /tmp/.i.js and Node.js processes, and rotating appliance, VPN, LDAP, wireless and IPSec credentials.
Coverage timelineoldest first · each row is one article
- · 7d agoCVE-2025-25249 Exploitation Delivers PivotC2, a FortiGate Post-Exploitation RAT
SOCRadar· 74
Attackers exploiting CVE-2025-25249 in Fortinet FortiGate firewalls deploy PivotC2, a post-exploitation RAT, on exposed edge devices.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-25249 | Heap-Based Buffer Overflow in Fortinet FortiOS, FortiSwitchManager, and FortiSASE CVE-2025-25249 is a heap-based buffer overflow (CWE-122/CWE-787) in Fortinet FortiOS, FortiSwitchManager, and FortiSASE that allows an attacker to execute unauthorized code or commands. It is triggered by sending specially crafted packets to an affected device, causing an out-of-bounds write in heap memory that can be leveraged for code execution. Successful exploitation gives attackers command execution on the appliance; in observed intrusions against FortiGate firewalls, attackers have deployed custom Node.js malware and a post-exploitation RAT dubbed PivotC2. Any organization running the affected Fortinet products is at risk, with internet-facing FortiGate firewalls the primary concern. The flaw was added to CISA's KEV on 2026-09-09, confirming active exploitation in the wild (ransomware use unknown); no public PoC is known. Do: Upgrade FortiOS, FortiSwitchManager, and FortiSASE in accordance with Fortinet's advisory (specific fixed versions are not listed in the available data), prioritizing internet-exposed FortiGate firewalls per CISA KEV and BOD 26-04 timelines. Hunt for signs of compromise, including custom Node.js malware and the PivotC2 RAT, on FortiGate devices, and review exposure and access logs for admin/SSL-VPN interfaces. If patching is not possible, apply vendor-recommended mitigations or, per BOD 26-04, discontinue use of the exposed product. | 9.8 | 2% | KEV PoC |
| mass≈300,000–500,000 internet-exposed FortiGate/FortiOS devices (plus FortiSASE cloud tenants) | |
| CVE-2025-47855 | An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in Fortinet FortiFone 7.0.0 through 7.0.1, FortiFone 3.0.13 through 3.0.23 An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in Fortinet FortiFone 7.0.0 through 7.0.1, FortiFone 3.0.13 through 3.0.23 allows an unauthenticated attacker to obtain the device configuration via crafted HTTP or HTTPS requests. NVD description · AI analysis pending | 9.8 | <1% | — | — | ||
| CVE-2025-64155 | Unauthenticated RCE via OS Command Injection in Fortinet FortiSIEM Fortinet FortiSIEM contains an unauthenticated OS command injection flaw (CWE-78) caused by improper neutralization of special elements used in an OS command. A remote attacker can trigger it by sending crafted TCP requests to the vulnerable service, requiring no credentials or user interaction. Successful exploitation allows execution of unauthorized code or commands on the SIEM host, giving an attacker control over a high-value security monitoring platform. Every current FortiSIEM release branch is affected: 7.4.0, 7.3.0 through 7.3.4, 7.1.0 through 7.1.8, 7.0.0 through 7.0.4, and 6.7.0 through 6.7.10. A public proof-of-concept exploit has been released, and EPSS assigns a 43.2% probability of exploitation within 30 days (99th percentile), though the flaw is not yet in CISA KEV and no confirmed in-the-wild exploitation has been reported. Do: Upgrade FortiSIEM to the fixed release specified in Fortinet's advisory for CVE-2025-64155 as soon as possible, since exploitation requires only network reachability and no authentication. Until patched, restrict access to FortiSIEM's network-facing TCP services (management and event-ingestion interfaces) to trusted management networks and sources. Given the public proof-of-concept and high EPSS score, prioritize checking internet-exposed FortiSIEM instances for signs of exploitation and review logs for unexpected command execution. | 9.8 | 45% | PoC |
| largetens of thousands of FortiSIEM deployments worldwide (all current 6.7.x-7.4.x release branches affected) |