Fortinet CVE-2025-25249: PivotC2 Node.js RAT on FortiGate after cw_acd RCE

By George Bailey   Published: 09/10/26   Updated: 09/10/26   2 min read

What Changed

SOCRadar reports that Russian-speaking cybercrime actors have been exploiting CVE-2025-25249—an unauthenticated heap-based buffer overflow in the FortiOS and FortiSwitchManager cw_acd (CAPWAP) daemon—to deploy PivotC2, a Node.js remote access trojan purpose-built for FortiGate post-exploitation. Fortinet advisory FG-IR-25-084 states the bug may allow a remote unauthenticated attacker to execute arbitrary code or commands via crafted requests, while noting that ASLR and PIE raise exploit complexity. Patches shipped in January 2026.

Score the severity carefully in triage meetings: Fortinet rates the issue CVSS 7.4; NVD and SOCRadar cite 9.8. That disagreement is material for prioritization debates—exploitation status is not. CISA added CVE-2025-25249 to KEV on September 9, 2026 with a compressed BOD 26-04 window and forensic-triage expectations for internet-exposed assets.

Victim counts (SOCRadar-derived): attackers targeted more than 30,000 IP addresses; SOCRadar reports 178 devices infected with PivotC2, concentrated in the United States, with at least two intrusions progressing to confirmed data exfiltration. Treat these figures as SOCRadar’s campaign telemetry, not a global census. Reported PivotC2 capabilities include interactive shell, traffic tunneling, network scanning, and configuration or credential harvesting.

Why This Matters Operationally

Perimeter firewalls that speak CAPWAP on UDP 5246–5249—especially with fabric or CAPWAP access enabled on internet-facing interfaces—are the entry condition. Once PivotC2 lands, operators lose the assumption that “the FortiGate is the trusted chokepoint.” Unauthenticated RCE on firewall OS plus a native RAT observed since at least July 2026 closes the 7.4-versus-9.8 debate for anyone still waiting.

What Defenders Should Verify First

Source Context

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.