An unauthenticated CAPWAP heap overflow in FortiOS is not theoretical anymore: operators have been using it to drop PivotC2, a Node.js RAT purpose-built for FortiGate post-exploitation — including config and credential theft.
If wireless / CAPWAP is in play on FortiGate or FortiSwitchManager, patch status from January only helps if you actually took the fixed builds.
What happened
Fortinet patched CVE-2025-25249 (heap overflow in the cw_acd CAPWAP daemon, listening unauthenticated on UDP 5246) in January 2026. SOCRadar reports financially motivated operators have exploited it since at least July 2026, targeting tens of thousands of FortiGate IPs and infecting on the order of 178 devices with PivotC2.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
CISA added the CVE to KEV on September 9, 2026 with a federal due date of September 12. Confirmed US intrusions included further pivoting, credential theft, and mailbox exfiltration after the firewall foothold.
Why it matters
Firewall compromise is VPN PSK, LDAP bind, and admin-hash territory. PivotC2 is built to harvest those stores and tunnel deeper.
CAPWAP is easy to forget in “management plane only” hardening checklists — this one does not need the HTTPS admin UI.
What to do first
- Upgrade FortiOS to 7.6.4 / 7.4.9 / 7.2.12 / 7.0.18 (or newer) and FortiSwitchManager to 7.2.7 / 7.0.6.
- Restrict or monitor UDP 5246 exposure; inventory which devices still speak CAPWAP toward untrusted networks.
- If compromise is plausible: isolate, preserve forensics, rotate VPN PSKs, LDAP/admin credentials, and any secrets stored on the box.
- Hunt PivotC2-style artifacts (research cites paths like
/tmp/.i.js) and odd outbound TLS / reverse-SSH from the firewall. - Re-issue certificates and review firewall config diffs since July.
Details
- CVE: CVE-2025-25249
- Products: FortiOS (6.4–7.6.3 trains as advised) · FortiSwitchManager · FortiSASE variants per vendor notes
- Vector: Unauthenticated CAPWAP heap overflow (
cw_acd, UDP 5246) - KEV: Added 2026-09-09; federal due 2026-09-12
- Malware: PivotC2 (Node.js RAT)
Hunt / verify
- Confirm FortiOS / FortiSwitchManager build ≥ fixed releases.
- Review CAPWAP-facing exposure and post-July config / admin changes.
- Search for PivotC2 indicators and unexpected Node processes on the appliance.
Sources
- SecurityWeek: Fortinet flaw exploited in PivotC2 RAT attacks
- CISA: Four KEVs added Sep 9, 2026 (includes CVE-2025-25249)
- Fortinet PSIRT advisories
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.