ZeroHour
Story · 1 source · 1 articlefirst updated ()

Fortinet CVE-2025-25249 Actively Exploited to Deploy PivotC2 RAT; CISA Adds Flaw to KEV Catalog

criticalExploit / PoCexploited in the wildimportance 91CVE-2025-25249CVE-2025-47855CVE-2025-64155
What's new: This is the first merged summary for this story. Reporting began with SOCRadar's disclosure of active exploitation and the PivotC2 campaign (September 8), followed by CISA adding CVE-2025-25249 to its KEV catalog on September 9 with a three-day federal patch deadline under BOD 26-04, and the Canadian Cyber Centre updating advisory AV26-023 the same day. Later reporting (September 10) added CISA's…
Merged summary · glm-5.3 · rewritten as coverage arrives

Threat actors are exploiting heap buffer overflow CVE-2025-25249 in FortiOS/FortiSwitchManager's cw_acd daemon to deploy the Node.js PivotC2 RAT, compromising 178 of over 30,000 scanned FortiGate devices since July 2026; CISA added the flaw to its KEV catalog…

SOCRadar's Threat Research Unit reports active exploitation of CVE-2025-25249, a heap-based buffer overflow (CWE-122/CWE-787) in the cw_acd daemon of FortiOS and FortiSwitchManager, triggered via specially crafted CAPWAP requests to UDP port 5246. SOCRadar-based reports rate it CVSS 9.8, while SecurityWeek cites CVSS 7.4. Affected versions include FortiOS 6.4-7.6.3 and FortiSwitchManager 7.0.x/7.2.x, with one report also listing FortiSASE as affected. The flaw was patched in January 2026 via FortiOS 7.6.4/7.4.9/7.2.12/7.0.18 and FortiSwitchManager 7.2.7/7.0.6. Attackers scanned over 30,000 internet-exposed FortiGate IP addresses and compromised at least 178 devices since July 2026, deploying fortirun.bin and PivotC2, a Node.js post-exploitation framework providing interactive shells, SOCKS5/HTTP proxying, port forwarding, network scanning, and automated configuration harvesting. PivotC2 decrypts fsv_sync.dat using AES-256-CBC and AES-128-GCM, exposing VPN pre-shared keys, SSL-VPN, admin, wireless, and LDAP credentials. Two US organizations suffered confirmed full-network intrusions with Exchange mailbox (.pst) exfiltration to Wasabi S3 storage; activity included AD enumeration, browser credential theft, and RDP enablement. The US is the most affected country, followed by Chile, Colombia, and the UK. SOCRadar attributes the campaign to a likely Russian-speaking, financially motivated cybercrime operator and assesses the RAT was AI-assisted. On September 9, 2026, CISA added CVE-2025-25249 to its Known Exploited Vulnerabilities catalog, imposing a three-day patch deadline (September 12, 2026) for federal agencies under BOD 26-04 and requiring forensic triage of affected environments rather than routine patching alone. The Canadian Cyber Centre updated advisory AV26-023 relaying the January 2026 Fortinet advisories, which also cover related flaws CVE-2025-47855 (unauthenticated local configuration access) and CVE-2025-64155 (unauthenticated remote command injection) across FortiFone, FortiOS, FortiSASE, FortiSIEM, and FortiSwitchManager. Recommended actions include blocking UDP ports 5246-5249, hunting for /tmp/.i.js and rogue Node.js processes, patching, and rotating appliance, VPN, LDAP, wireless, and IPSec credentials. Ransomware use is currently listed as unknown.

  • CVE-2025-25249: heap-based buffer overflow in the cw_acd daemon exploited via crafted CAPWAP packets on UDP 5246, allowing unauthenticated remote code execution
  • Sources disagree on severity: CVSS 9.8 (Cyber Security News, GBHackers) vs CVSS 7.4 (SecurityWeek)
  • Affected software: FortiOS 6.4-7.6.3 and FortiSwitchManager 7.0.x/7.2.x; one report also lists FortiSASE; patched January 2026 in FortiOS 7.6.4/7.4.9/7.2.12/7.0.18 and FortiSwitchManager 7.2.7/7.0.6
  • 30,000+ internet-exposed FortiGate IPs scanned; 178 devices compromised since July 2026
  • PivotC2 Node.js RAT offers shells, SOCKS5/HTTP proxying, port forwarding, scanning, and config harvesting; decrypts fsv_sync.dat (AES-256-CBC, AES-128-GCM) to steal VPN pre-shared keys, SSL-VPN, admin, wireless, and LDAP credentials
  • Two confirmed full-network intrusions of US organizations with Exchange .pst exfiltration to Wasabi S3; US most affected, then Chile, Colombia, UK
  • Attribution: likely Russian-speaking, financially motivated cybercrime operator; AI-assisted tooling suspected
  • CISA added CVE-2025-25249 to the KEV catalog on September 9, 2026; BOD 26-04 sets a September 12, 2026 federal patch deadline and mandates forensic triage

Coverage timeline

  1. · 7d ago
    Cyber Security News· 91
    Hackers Actively Exploiting FortiGate Firewalls to Deploy Custom Node.js Malware

    Attackers actively exploit CVE-2025-25249 in FortiGate firewalls to deploy PivotC2, a Node.js RAT that decrypts VPN and admin credentials.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-25249
Heap-Based Buffer Overflow in Fortinet FortiOS, FortiSwitchManager, and FortiSASE

CVE-2025-25249 is a heap-based buffer overflow (CWE-122/CWE-787) in Fortinet FortiOS, FortiSwitchManager, and FortiSASE that allows an attacker to execute unauthorized code or commands. It is triggered by sending specially crafted packets to an affected device, causing an out-of-bounds write in heap memory that can be leveraged for code execution. Successful exploitation gives attackers command execution on the appliance; in observed intrusions against FortiGate firewalls, attackers have deployed custom Node.js malware and a post-exploitation RAT dubbed PivotC2. Any organization running the affected Fortinet products is at risk, with internet-facing FortiGate firewalls the primary concern. The flaw was added to CISA's KEV on 2026-09-09, confirming active exploitation in the wild (ransomware use unknown); no public PoC is known.

Do: Upgrade FortiOS, FortiSwitchManager, and FortiSASE in accordance with Fortinet's advisory (specific fixed versions are not listed in the available data), prioritizing internet-exposed FortiGate firewalls per CISA KEV and BOD 26-04 timelines. Hunt for signs of compromise, including custom Node.js malware and the PivotC2 RAT, on FortiGate devices, and review exposure and access logs for admin/SSL-VPN interfaces. If patching is not possible, apply vendor-recommended mitigations or, per BOD 26-04, discontinue use of the exposed product.

9.82% KEV PoC
  • Fortinet FortiOS
  • Fortinet FortiSwitchManager
  • Fortinet FortiSASE
mass≈300,000–500,000 internet-exposed FortiGate/FortiOS devices (plus FortiSASE cloud tenants)
CVE-2025-47855
An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in Fortinet FortiFone 7.0.0 through 7.0.1, FortiFone 3.0.13 through 3.0.23

An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in Fortinet FortiFone 7.0.0 through 7.0.1, FortiFone 3.0.13 through 3.0.23 allows an unauthenticated attacker to obtain the device configuration via crafted HTTP or HTTPS requests.

NVD description · AI analysis pending
9.8<1%
CVE-2025-64155
Unauthenticated RCE via OS Command Injection in Fortinet FortiSIEM

Fortinet FortiSIEM contains an unauthenticated OS command injection flaw (CWE-78) caused by improper neutralization of special elements used in an OS command. A remote attacker can trigger it by sending crafted TCP requests to the vulnerable service, requiring no credentials or user interaction. Successful exploitation allows execution of unauthorized code or commands on the SIEM host, giving an attacker control over a high-value security monitoring platform. Every current FortiSIEM release branch is affected: 7.4.0, 7.3.0 through 7.3.4, 7.1.0 through 7.1.8, 7.0.0 through 7.0.4, and 6.7.0 through 6.7.10. A public proof-of-concept exploit has been released, and EPSS assigns a 43.2% probability of exploitation within 30 days (99th percentile), though the flaw is not yet in CISA KEV and no confirmed in-the-wild exploitation has been reported.

Do: Upgrade FortiSIEM to the fixed release specified in Fortinet's advisory for CVE-2025-64155 as soon as possible, since exploitation requires only network reachability and no authentication. Until patched, restrict access to FortiSIEM's network-facing TCP services (management and event-ingestion interfaces) to trusted management networks and sources. Given the public proof-of-concept and high EPSS score, prioritize checking internet-exposed FortiSIEM instances for signs of exploitation and review logs for unexpected command execution.

9.845% PoC
  • Fortinet FortiSIEM 7.4.0
  • Fortinet FortiSIEM 7.3.0 - 7.3.4
  • Fortinet FortiSIEM 7.1.0 - 7.1.8
  • +2 more
largetens of thousands of FortiSIEM deployments worldwide (all current 6.7.x-7.4.x release branches affected)