ZeroHour
Story · 4 sources · 4 articlesfirst updated ()

Fortinet CVE-2025-25249 Exploited to Deploy PivotC2 RAT; CISA Adds Flaw to KEV Catalog

criticalExploit / PoCexploited in the wildimportance 85CVE-2025-25249CVE-2025-47855CVE-2025-64155
What's new: First merged summary for this story. Initial reporting establishes active exploitation of CVE-2025-25249 with the PivotC2 RAT (178 of 30,000+ targets infected since July 2026), and CISA's addition of the flaw to the KEV catalog on September 9, 2026, with a September 12 federal remediation deadline under BOD 26-04.
Merged summary · glm-5.3 · rewritten as coverage arrives

Attackers are exploiting a heap-based buffer overflow in FortiOS/FortiSwitchManager's cw_acd daemon (CVE-2025-25249) to deploy the PivotC2 Node.js RAT, infecting 178 of more than 30,000 scanned targets; CISA added the CVE to its KEV catalog on September 9,…

SOCRadar's Threat Research Unit reports active exploitation of CVE-2025-25249, a heap-based buffer overflow (CWE-122/CWE-787) in the cw_acd daemon of FortiOS and FortiSwitchManager, triggered via crafted CAPWAP requests to UDP port 5246 and patched in January 2026. Sources disagree on severity: GBHackers cites a CVSS score of 9.8, while SecurityWeek reports 7.4. Attackers scanned more than 30,000 IP addresses and compromised at least 178 internet-exposed FortiGate devices since July 2026, most in the US, followed by Chile, Colombia, and the UK. The campaign deploys PivotC2, an AI-assisted Node.js RAT offering interactive shells, SOCKS5/HTTP proxying, port forwarding, network scanning, and configuration harvesting that decrypts stored FortiGate credentials (including VPN pre-shared keys, SSL-VPN credentials, and LDAP secrets). Russian-language artifacts, AD enumeration, browser credential theft, RDP enablement, and exfiltration of Exchange .pst files to Wasabi S3 point to a likely Russian-speaking, financially motivated group; two US organizations suffered confirmed intrusions with data exfiltration. CISA added the CVE to its Known Exploited Vulnerabilities catalog on September 9, 2026, imposing a three-day September 12 remediation deadline under BOD 26-04 and requiring forensic triage, not just patching. Ransomware involvement is currently listed as unknown. Fixes are available in FortiOS 7.6.4/7.4.9/7.2.12/7.0.18 and FortiSwitchManager 7.2.7/7.0.6. A related Canadian Cyber Centre advisory (AV26-023) notes additional Fortinet flaws CVE-2025-47855 (unauthenticated local configuration access) and CVE-2025-64155 (unauthenticated remote command injection) across FortiFone, FortiOS, FortiSASE, FortiSIEM, and FortiSwitchManager. Recommended mitigations include blocking UDP ports 5246-5249, hunting for /tmp/.i.js and suspicious Node.js processes, and rotating appliance, VPN, LDAP, wireless, and IPSec credentials.

  • CVE-2025-25249 is a heap-based buffer overflow (CWE-122/CWE-787) in the cw_acd daemon of FortiOS and FortiSwitchManager, exploited via crafted CAPWAP packets to UDP port 5246; sources disagree on CVSS: 9.8 (GBHackers/SOCRadar) vs 7.4…
  • Attackers scanned more than 30,000 IP addresses and infected 178 devices with the PivotC2 RAT since July 2026; affected countries led by the US, then Chile, Colombia, and the UK
  • PivotC2 is an AI-assisted Node.js RAT providing shells, SOCKS5/HTTP proxying, port forwarding, scanning, and decryption of stored FortiGate credentials including VPN pre-shared keys, SSL-VPN, and LDAP secrets
  • SOCRadar attributes the campaign to a likely Russian-speaking, financially motivated actor; two US organizations had confirmed intrusions with data exfiltration, including Exchange .pst files sent to Wasabi S3
  • CISA added CVE-2025-25249 to its KEV catalog on September 9, 2026, with a three-day BOD 26-04 patch deadline of September 12 for federal agencies and mandatory forensic triage of affected environments; ransomware use is currently unknown
  • Patches available in FortiOS 7.6.4/7.4.9/7.2.12/7.0.18 and FortiSwitchManager 7.2.7/7.0.6; the flaw was patched in January 2026 per Fortinet advisories relayed in Canadian Cyber Centre advisory AV26-023
  • Related Fortinet vulnerabilities flagged in the same advisory set: CVE-2025-47855 (unauthenticated local configuration access) and CVE-2025-64155 (unauthenticated remote command injection), affecting FortiFone, FortiOS, FortiSASE,…
  • Detection/mitigation guidance: block UDP ports 5246-5249, hunt for /tmp/.i.js and suspicious Node.js processes, and rotate appliance, VPN, LDAP, wireless, and IPSec credentials

Coverage timeline

  1. · 6d ago
    GBHackers· 72
    Hackers Exploit Critical FortiGate Flaw to Deploy AI-Assisted PivotC2 RAT

    SOCRadar says attackers exploit FortiGate CVE-2025-25249 to deploy the PivotC2 Node.js RAT, compromising 178 of 30,000 targeted devices and stealing credentials.

  2. · 6d ago
    Canadian Centre for Cyber Security· 60
    Fortinet security advisory (AV26-023) - Update 1

    CISA added Fortinet CVE-2025-25249, a heap-based buffer overflow in the cw_acd daemon, to its KEV catalog; Canadian Cyber Centre urges patching.

  3. · 5d ago
    SecurityWeek· 82
    Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks

    Threat actors exploit Fortinet heap-based buffer overflow CVE-2025-25249 to deploy PivotC2 RAT, infecting 178 devices and exfiltrating data from US targets.

  4. · 5d ago
    Cyber Security News· 85
    CISA Warns of Fortinet Heap-based Buffer Overflow Flaw Exploited in Attacks

    CISA added actively exploited Fortinet CVE-2025-25249, a critical heap-based buffer overflow in FortiOS, FortiSwitchManager, and FortiSASE, to its KEV catalog.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-25249
Heap-Based Buffer Overflow in Fortinet FortiOS, FortiSwitchManager, and FortiSASE

CVE-2025-25249 is a heap-based buffer overflow (CWE-122/CWE-787) in Fortinet FortiOS, FortiSwitchManager, and FortiSASE that allows an attacker to execute unauthorized code or commands. It is triggered by sending specially crafted packets to an affected device, causing an out-of-bounds write in heap memory that can be leveraged for code execution. Successful exploitation gives attackers command execution on the appliance; in observed intrusions against FortiGate firewalls, attackers have deployed custom Node.js malware and a post-exploitation RAT dubbed PivotC2. Any organization running the affected Fortinet products is at risk, with internet-facing FortiGate firewalls the primary concern. The flaw was added to CISA's KEV on 2026-09-09, confirming active exploitation in the wild (ransomware use unknown); no public PoC is known.

Do: Upgrade FortiOS, FortiSwitchManager, and FortiSASE in accordance with Fortinet's advisory (specific fixed versions are not listed in the available data), prioritizing internet-exposed FortiGate firewalls per CISA KEV and BOD 26-04 timelines. Hunt for signs of compromise, including custom Node.js malware and the PivotC2 RAT, on FortiGate devices, and review exposure and access logs for admin/SSL-VPN interfaces. If patching is not possible, apply vendor-recommended mitigations or, per BOD 26-04, discontinue use of the exposed product.

9.82% KEV PoC
  • Fortinet FortiOS
  • Fortinet FortiSwitchManager
  • Fortinet FortiSASE
mass≈300,000–500,000 internet-exposed FortiGate/FortiOS devices (plus FortiSASE cloud tenants)
CVE-2025-47855
An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in Fortinet FortiFone 7.0.0 through 7.0.1, FortiFone 3.0.13 through 3.0.23

An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in Fortinet FortiFone 7.0.0 through 7.0.1, FortiFone 3.0.13 through 3.0.23 allows an unauthenticated attacker to obtain the device configuration via crafted HTTP or HTTPS requests.

NVD description · AI analysis pending
9.8<1%
CVE-2025-64155
Unauthenticated RCE via OS Command Injection in Fortinet FortiSIEM

Fortinet FortiSIEM contains an unauthenticated OS command injection flaw (CWE-78) caused by improper neutralization of special elements used in an OS command. A remote attacker can trigger it by sending crafted TCP requests to the vulnerable service, requiring no credentials or user interaction. Successful exploitation allows execution of unauthorized code or commands on the SIEM host, giving an attacker control over a high-value security monitoring platform. Every current FortiSIEM release branch is affected: 7.4.0, 7.3.0 through 7.3.4, 7.1.0 through 7.1.8, 7.0.0 through 7.0.4, and 6.7.0 through 6.7.10. A public proof-of-concept exploit has been released, and EPSS assigns a 43.2% probability of exploitation within 30 days (99th percentile), though the flaw is not yet in CISA KEV and no confirmed in-the-wild exploitation has been reported.

Do: Upgrade FortiSIEM to the fixed release specified in Fortinet's advisory for CVE-2025-64155 as soon as possible, since exploitation requires only network reachability and no authentication. Until patched, restrict access to FortiSIEM's network-facing TCP services (management and event-ingestion interfaces) to trusted management networks and sources. Given the public proof-of-concept and high EPSS score, prioritize checking internet-exposed FortiSIEM instances for signs of exploitation and review logs for unexpected command execution.

9.845% PoC
  • Fortinet FortiSIEM 7.4.0
  • Fortinet FortiSIEM 7.3.0 - 7.3.4
  • Fortinet FortiSIEM 7.1.0 - 7.1.8
  • +2 more
largetens of thousands of FortiSIEM deployments worldwide (all current 6.7.x-7.4.x release branches affected)