CVE / NVD / KEV
Vendor advisories
CVE-2025-25249 is an actively exploited Fortinet flaw used to deploy PivotC2 for credential theft, internal tunneling, and network access.
An active campaign exploiting Fortinet vulnerability CVE-2025-25249 is compromising FortiGate appliances and deploying PivotC2, a purpose-built remote access tool capable of stealing firewall-stored credentials and providing access into internal networks.
The SOCRadar Threat Research Unit disclosed the campaign on September 8, 2026, reporting exploitation dating back to at least July. Files recovered during its investigation contained more than 30,000 targeted FortiGate IP addresses and records for 178 devices that SOCRadar assessed as successfully exploited and infected with PivotC2. These figures describe SOCRadar's recovered campaign dataset, not a global count of compromised Fortinet devices.
On September 9, CISA added CVE-2025-25249 to its Known Exploited Vulnerabilities (KEV) Catalog, independently confirming exploitation in the wild. The KEV addition does not independently validate SOCRadar's infection totals, victimology, or attribution. The Canadian Centre for Cyber Security also updated its advisory that day to record the KEV addition.
PivotC2 is tailored to FortiGate environments. According to SOCRadar, the tool can extract and decrypt credentials from FortiGate configurations, scan internal networks, establish proxy tunnels and port forwards, transfer files, and provide interactive shell access. SOCRadar reconstructed two intrusions against U.S. organizations in which activity progressed into internal networks and ultimately resulted in data exfiltration.
CVE-2025-25249 enables unauthenticated remote code execution
CVE-2025-25249 is a heap-based buffer overflow in Fortinet's `cw_acd` daemon. Fortinet's FG-IR-25-084 advisory identifies affected FortiOS, FortiSwitchManager, and FortiSASE releases. The daemon handles Control and Provisioning of Wireless Access Points (CAPWAP) traffic used for centralized wireless access-point management.
Specially crafted packets can trigger the flaw and allow a remote, unauthenticated attacker to execute unauthorized code or commands. Fortinet published its advisory on January 13, 2026. The Canadian Centre for Cyber Security subsequently directed affected organizations to apply the necessary updates.
Severity figures differ by scoring authority. Fortinet CNA data assigns CVE-2025-25249 a CVSS v3.1 base score of 8.1 (High), using a vector with high attack complexity, while NVD has scored the vulnerability 9.8 (Critical). Confirmed exploitation increases its operational priority regardless of the scoring difference.
Affected releases include:
- FortiOS 7.6.0 through 7.6.3
- FortiOS 7.4.0 through 7.4.8
- FortiOS 7.2.0 through 7.2.11
- FortiOS 7.0.0 through 7.0.17
- FortiOS 6.4.0 through 6.4.16
- FortiSwitchManager 7.2.0 through 7.2.6
- FortiSwitchManager 7.0.0 through 7.0.5
- FortiSASE 25.2.b and 25.1.a.2
The affected FortiOS, FortiSwitchManager, and FortiSASE versions are corroborated by current vulnerability and government records. Fortinet's release documentation, for example, confirms that FortiOS 7.6.4, 7.4.9, and 7.2.12 are no longer vulnerable to CVE-2025-25249.
Exploitation deploys PivotC2
SOCRadar recovered an attacker exploit framework named `fortirun.bin`. Its analysis indicates that the framework targets CVE-2025-25249 and accepts information including the target FortiGate address, CAPWAP port, attacker's listener address and port, and a Base64-encoded payload. In the observed attack chain, SOCRadar found the exploit using UDP port 5246, the default CAPWAP Control port.
According to SOCRadar, successful exploitation establishes a reverse shell and executes JavaScript through Node.js. The initial JavaScript stager retrieves and decodes the next stage, ultimately writing the PivotC2 client to:
/tmp/.i.jsPivotC2 then maintains an outbound TLS connection to its command-and-control infrastructure. Attacker control can therefore operate through a connection initiated by the compromised firewall rather than depending on a new inbound C2 connection.
In the campaign documented by SOCRadar, successful exploitation consequently turns the FortiGate appliance into an attacker-controlled pivot at the network boundary rather than limiting the compromise to the firewall itself.
PivotC2 automates credential theft and internal discovery
SOCRadar describes PivotC2 as a Node.js post-exploitation framework purpose-built for compromised FortiGate appliances. Reported capabilities include interactive command shells, file upload and download, SOCKS5 and HTTP proxies, local and remote port forwarding, CIDR-range network scanning, and FortiGate configuration harvesting with automated credential decryption.
A particularly significant capability is the extraction and decryption of secrets stored in FortiGate configuration data. Depending on the device configuration, exposed material can include administrator accounts, SSL-VPN credentials, LDAP bind credentials, wireless pre-shared keys, and IPsec/VPN pre-shared keys.
PivotC2 also provides an automated operating mode. When enabled, a newly connected client undergoes configuration harvesting, credential decryption, internal-interface extraction, and port scanning without continued manual operator input. SOCRadar reports that the automated scanning covers discovered networks and predefined private ranges and targets ports associated with services including SSH, HTTP/S, LDAP, SMB, VMware, SQL databases, and RDP.
This capability has direct implications for incident response. Applying a fixed release closes the vulnerability, but it does not invalidate credentials that may already have been extracted or establish whether an attacker subsequently accessed other systems.
Two investigated intrusions progressed beyond the firewall
SOCRadar found 178 confirmed PivotC2 victim sessions within the campaign data it analyzed. Infections were most heavily concentrated in the United States, followed by Chile, Colombia, and the United Kingdom. These geographic findings describe SOCRadar's dataset and should not be interpreted as a comprehensive measurement of CVE-2025-25249 exploitation.
Researchers also reconstructed broader intrusions affecting two U.S.-based organizations. According to SOCRadar, activity progressed from CVE-2025-25249 exploitation and PivotC2 deployment into internal tunneling and host discovery, browser credential extraction, lateral movement, and data exfiltration.
Recovered tooling included `ldapdomaindump` for Active Directory enumeration and a Rust-based SSH utility used for reverse-SSH relays. SOCRadar also identified tooling that packaged and exfiltrated Microsoft Exchange `.pst` mailbox files to attacker-controlled Wasabi S3 storage.
SOCRadar assesses with high confidence that the observed operation is associated with a Russian-speaking, financially motivated cybercrime actor. Its assessment cites evidence including Russian-language comments, exfiltration tradecraft, and discovery of storage and backup infrastructure. This remains SOCRadar's attribution assessment rather than an independently established government attribution.
No reviewed evidence establishes PivotC2 victims specifically in Saudi Arabia, the UAE, or Oman.
What defenders should do
Organizations operating affected systems should treat CVE-2025-25249 as an actively exploited vulnerability rather than prioritizing it solely by its numerical severity score.
FortiOS should be upgraded to a fixed release appropriate for the installed branch: 7.6.4 or later, 7.4.9 or later, 7.2.12 or later, 7.0.18 or later, or 6.4.17 or later. FortiSwitchManager 7.2 deployments should move to 7.2.7 or later and 7.0 deployments to 7.0.6 or later. Fortinet's release notes independently confirm remediation of CVE-2025-25249 in FortiOS 7.6.4, 7.4.9, and 7.2.12.
Where an immediate upgrade cannot be completed, Fortinet's documented workaround, reproduced by SOCRadar, is to disable or restrict the `fabric` service on exposed interfaces or implement a local-in policy to block or restrict incoming UDP traffic on CAPWAP Control ports 5246-5249. Organizations should validate these changes against legitimate Fortinet wireless-management requirements before deployment.
Threat hunting should extend beyond checking the installed firmware version. SOCRadar published the following PivotC2 infrastructure:
146[.]103[.]99[.]177
46[.]151[.]29[.]58Responders should also inspect FortiGate systems for `/tmp/.i.js`, unexpected Node.js activity, and suspicious outbound connections. SOCRadar's report provides additional hashes and network indicators, including the SHA-256 hash of `fortirun.bin` and hashes for multiple PivotC2 stagers and clients.
Matches to these indicators should trigger investigation beyond the firewall. Because PivotC2 is designed to harvest configuration secrets and provide internal tunnels, credentials potentially exposed through a compromised appliance should not be considered trustworthy merely because the vulnerable device has subsequently been patched.
If compromise is suspected or PivotC2 artifacts are identified, responders should treat FortiGate configuration secrets as potentially exposed. Relevant administrator passwords, SSL-VPN credentials, LDAP bind secrets, wireless PSKs, and IPsec pre-shared keys contained in the configuration should be rotated. Investigation should also examine subsequent use of those credentials, unexpected internal scanning, proxy or tunnel activity, browser credential access, lateral movement, and data exfiltration consistent with the activity documented by SOCRadar.
For a structured approach to patching, monitoring, and incident readiness across edge devices, see our guide to Managed Cybersecurity for GCC SMBs.
Patching does not resolve prior compromise
CVE-2025-25249 requires two distinct remediation actions when exploitation may have occurred: closing the initial access path and determining what happened before it was closed. CISA's September 9, 2026 KEV addition independently establishes exploitation in the wild, while SOCRadar's investigation documents a campaign in which attackers converted FortiGate compromise into credential theft and internal tunneling and, in two investigated U.S. incidents, broader network intrusion and data exfiltration.
For FortiGate environments that ran vulnerable releases with the affected CAPWAP service exposed to untrusted networks, upgrading to an appropriate fixed release is the immediate priority. Systems with suspicious indicators also require investigation to determine whether PivotC2 harvested credentials or enabled activity elsewhere in the network before remediation.
Once reusable secrets have been extracted or an attacker has established access to internal systems, patching CVE-2025-25249 alone does not remediate the resulting compromise.
Cyberactics Security Team
Managed Security Services
We help SMBs across Jordan, Saudi Arabia, Oman, and the UAE respond to active threats and validate exposure across their environments.
Talk to an incident response engineer
Book a 30-minute call and we'll walk through exposure assessment, patch validation, and post-remediation investigation for your environment.



