Fortinet FortiOS CVE-2025-25249: CAPWAP Heap Overflow to PivotC2 RAT

By George Bailey   Published: 09/15/26   Updated: 09/15/26   2 min read

An unauthenticated CAPWAP heap overflow in FortiOS is not theoretical anymore: operators have been using it to drop PivotC2, a Node.js RAT purpose-built for FortiGate post-exploitation — including config and credential theft.

If wireless / CAPWAP is in play on FortiGate or FortiSwitchManager, patch status from January only helps if you actually took the fixed builds.

What happened

Fortinet patched CVE-2025-25249 (heap overflow in the cw_acd CAPWAP daemon, listening unauthenticated on UDP 5246) in January 2026. SOCRadar reports financially motivated operators have exploited it since at least July 2026, targeting tens of thousands of FortiGate IPs and infecting on the order of 178 devices with PivotC2.

CISA added the CVE to KEV on September 9, 2026 with a federal due date of September 12. Confirmed US intrusions included further pivoting, credential theft, and mailbox exfiltration after the firewall foothold.

Why it matters

Firewall compromise is VPN PSK, LDAP bind, and admin-hash territory. PivotC2 is built to harvest those stores and tunnel deeper.

CAPWAP is easy to forget in “management plane only” hardening checklists — this one does not need the HTTPS admin UI.

What to do first

Details

Hunt / verify

Sources

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.