CVE-2025-25249 is a critical heap-based buffer overflow vulnerability affecting the cw_acd daemon in FortiOS and FortiSwitchManager, which handle CAPWAP-related communications on Fortinet edge devices. The vulnerability can be remotely exploited without authentication, potentially allowing attackers to execute arbitrary code or commands on vulnerable FortiGate appliances. SOCRadar identified an active exploitation campaign in which attackers weaponized this vulnerability to deploy PivotC2, a Node.js-based Remote Access Trojan specifically developed for compromised FortiGate devices. The campaign demonstrates the growing risk associated with public-facing firewalls and other network-edge infrastructure because compromise of these systems can provide attackers with a strategic entry point into internal environments. Attackers reportedly targeted more than 30,000 FortiGate IP addresses, with 178 devices confirmed to have been exploited and infected with PivotC2. The activity was concentrated primarily in the United States, with additional victims identified in several other countries. SOCRadar assessed the campaign as being associated with a financially motivated, Russian-speaking cybercrime operation.
The attack chain begins with an exploit binary, identified as fortirun.bin, supported by Bash and Python scripts that automate attempts against vulnerable FortiGate systems. Successful exploitation of CVE-2025-25249 enables attackers to establish a Node.js reverse shell and execute a JavaScript stager. The stager downloads a second-stage payload, decodes and XOR-decrypts it, and executes the resulting PivotC2 client on the compromised appliance. PivotC2 establishes an outbound TLS connection with the attacker-controlled command-and-control infrastructure, allowing communications to bypass traditional inbound firewall restrictions. The RAT provides interactive shell access, file transfer, SOCKS5 and HTTP proxy tunneling, local and remote port forwarding, network scanning, and FortiGate configuration harvesting. Its automated mode can collect configurations, decrypt stored credentials, identify internal network interfaces, and scan predefined or discovered internal ranges without continuous operator interaction. Harvested information may include VPN credentials, SSL-VPN accounts, wireless keys, LDAP credentials, and administrator secrets. In confirmed intrusions, attackers also performed internal discovery, credential theft, lateral movement, and data exfiltration.[/subscribe_to_unlock_form]
CVE-2025-25249 is a critical heap-based buffer overflow vulnerability affecting the cw_acd daemon in FortiOS and FortiSwitchManager, which handle CAPWAP-related communications on Fortinet edge devices. The vulnerability can be remotely exploited without authentication, potentially allowing attackers to execute arbitrary code or commands on vulnerable FortiGate appliances. SOCRadar identified an active exploitation campaign in which attackers weaponized this vulnerability to deploy PivotC2, a Node.js-based Remote Access Trojan specifically developed for compromised FortiGate devices. The campaign demonstrates the growing risk associated with public-facing firewalls and other network-edge infrastructure because compromise of these systems can provide attackers with a strategic entry point into internal environments. Attackers reportedly targeted more than 30,000 FortiGate IP addresses, with 178 devices confirmed to have been exploited and infected with PivotC2. The activity was concentrated primarily in the United States, with additional victims identified in several other countries. SOCRadar assessed the campaign as being associated with a financially motivated, Russian-speaking cybercrime operation.
The attack chain begins with an exploit binary, identified as fortirun.bin, supported by Bash and Python scripts that automate attempts against vulnerable FortiGate systems. Successful exploitation of CVE-2025-25249 enables attackers to establish a Node.js reverse shell and execute a JavaScript stager. The stager downloads a second-stage payload, decodes and XOR-decrypts it, and executes the resulting PivotC2 client on the compromised appliance. PivotC2 establishes an outbound TLS connection with the attacker-controlled command-and-control infrastructure, allowing communications to bypass traditional inbound firewall restrictions. The RAT provides interactive shell access, file transfer, SOCKS5 and HTTP proxy tunneling, local and remote port forwarding, network scanning, and FortiGate configuration harvesting. Its automated mode can collect configurations, decrypt stored credentials, identify internal network interfaces, and scan predefined or discovered internal ranges without continuous operator interaction. Harvested information may include VPN credentials, SSL-VPN accounts, wireless keys, LDAP credentials, and administrator secrets. In confirmed intrusions, attackers also performed internal discovery, credential theft, lateral movement, and data exfiltration.[emaillocker id="1283"]
The exploitation of CVE-2025-25249 highlights how vulnerabilities in internet-facing security appliances can evolve from initial access into broader network compromise. The deployment of PivotC2 is particularly significant because the malware is purpose-built for FortiGate environments and combines remote access, credential harvesting, network discovery, and tunneling capabilities in a single post-exploitation framework. Its automated operating mode can significantly reduce the amount of manual effort required by attackers after a successful compromise, enabling configuration collection, credential extraction, and internal network reconnaissance at scale. The confirmed compromise of two organizations beyond their FortiGate appliances demonstrates that the campaign can progress from edge-device exploitation to deeper enterprise intrusion and data theft. Organizations operating affected FortiOS or FortiSwitchManager versions should treat exposed appliances as high-priority assets and investigate them for signs of exploitation or PivotC2 activity. Security teams should also review outbound connections, unusual Node.js activity, configuration access, internal scanning, credential use, and suspicious tunneling from firewall infrastructure. Importantly, remediation should include credential rotation and incident investigation where compromise is suspected, because simply addressing the vulnerability may not remove an existing implant or invalidate previously stolen credentials.
We recommend you to update FortiOS to version 7.6.4, 7.4.9, 7.2.12, or 7.0.18 and FortiSwitchManager to version 7.2.7 or 7.0.6, or higher..
| Tactic | Technique Id | Technique | Sub-technique |
|---|---|---|---|
| Initial access | T1190 | Exploit Public | Facing Application- |
| Execution | T1059.001 | Command and Scripting Interpreter | PowerShell |
| Execution | T1059.004 | Command and Scripting Interpreter | Unix Shell |
| Execution | T1059.007 | Command and Scripting Interpreter | JavaScript |
| Defence Evasion | T1027 | Obfuscated Files or Information | - |
| Defence Evasion | T1036.009 | Masquerading | Break Process Trees |
| Defence Evasion | T1055.002 | Process Injection | Portable Executable Injection |
| Defence Evasion | T1070.004 | Indicator Removal | File Deletion |
| Discovery | T1046 | Network Service Discovery | - |
| Discovery | T1082 | System Information Discovery | - |
| Discovery | T1087.002 | Account Discovery | Domain Account |
The following reports contain further technical details:
[/emaillocker]