Active Exploitation
#threatreport #HighCompleteness
CVE-2025-25249 Exploitation Delivers PivotC2, a FortiGate Post-Exploitation RAT | 09-09-2026
Source: https://socradar.io/blog/cve-2025-25249-pivotc2-fortigate-rat/
Key details below ↓
🧑💻Actors/Campaigns:
Fortibleed
Lynx_ransomware
💀Threats:
Pivotc2, Portscan_tool, Credential_harvesting_technique, Proxychains_tool, Ldapdomaindump_tool, Obfs4proxy_tool, Passthehash_technique, Process_injection_technique,
🎯Victims: Fortigate firewalls, United states, Chile, Colombia, United kingdom
🌐Geo: United states, United kingdom, Colombia, Chile
🔓CVEs: CVE-2024-47575 \[[Vulners](https://vulners.com/cve/CVE-2024-47575)]
- CVSS V3.1: *9.8*,
- Vulners: Exploitation: True
Soft:
- fortinet fortimanager (<6.2.13, <6.4.15, <7.0.13, <7.2.8, <7.4.5)
- fortinet fortimanager_cloud (le6.4.7, <7.0.13, <7.2.8, <7.4.5)
CVE-2024-26304 \[[Vulners](https://vulners.com/cve/CVE-2024-26304)]
- CVSS V3.1: *9.8*,
- Vulners: Exploitation: Unknown
CVE-2026-35273 \[[Vulners](https://vulners.com/cve/CVE-2026-35273)]
- CVSS V3.1: *9.8*,
- Vulners: Exploitation: True
Soft:
- oracle peoplesoft_enterprise_peopletools (8.61, 8.62)
CVE-2025-25249 \[[Vulners](https://vulners.com/cve/CVE-2025-25249)]
- CVSS V3.1: *9.8*,
- Vulners: Exploitation: Unknown
Soft:
- fortinet fortios (<6.4.17, <7.0.18, <7.2.12, <7.4.9, <7.6.4)
📚TTPs:
⚔️Tactics: 8
🛠️Technics: 26
🧨IOCs:
- Url: 1
- File: 10
- IP: 7
- Hash: 12
💽Software: FortiGate, Node.js, busybox, Active Directory, SoftPerfect Network Scanner, Google Chrome, Chrome, Microsoft Edge, Microsoft Exchange, Linux, ...
📲Wallets: wassabi
🔢Algorithms: cbc, sha256, aes, xor, base64, aes-128-gcm, aes-256-cbc
🗂️Win API: VirtualAllocEx, WriteProcessMemory, OpenProcess
📜Programming Languages: rust, javascript, cpython, python, powershell
💻Platforms: arm
#threatreport:
CVE-2025-25249 is a critical heap-based buffer overflow in the `cw_acd` daemon used by FortiOS and FortiSwitchManager to process CAPWAP traffic on UDP port 5246. The vulnerability permits remote, unauthenticated code execution through specially crafted requests. A recovered exploit, `fortirun.bin`, targets vulnerable FortiGate and FortiAP devices, fingerprints supported firmware, performs heap grooming with malicious CAPWAP Add Station messages, corrupts allocator metadata, and hijacks control flow using an ARM64 ROP gadget. It then invokes the native Node.js runtime to establish a reverse shell.
The attack chain delivers a JavaScript stager that downloads an encrypted second-stage payload, Base64-decodes and XOR-decrypts it using the key `pivot`, writes it to `/tmp/.i.js`, and executes it in the background. The payload, PivotC2, is a Node.js remote access trojan designed for FortiGate appliances. It maintains an outbound TLS connection to its command-and-control server using a multiplexed binary protocol with channel support for shell access, command execution, file operations, port forwarding, and proxy services.
PivotC2 supports interactive shells, file upload and download, SOCKS5 and HTTP tunneling, local and remote port forwarding, network interface and process discovery, DNS resolution, CIDR-based port scanning, and cleanup of infection artifacts. It also harvests FortiGate configuration files, including VDOM data and `fsv_sync.dat`, then decrypts stored secrets. Recovered credentials may include VPN pre-shared keys, SSL-VPN accounts, wireless keys, LDAP credentials, and administrator passwords.
An automatic mode performs configuration harvesting, credential decryption, internal network extraction, and scans of discovered and predefined private ranges without operator intervention. The campaign’s files contained more than 30,000 target IP addresses and 178 confirmed infected sessions, concentrated primarily in the United States, Chile, Colombia, and the United Kingdom. Two US organizations experienced deeper intrusions involving internal tunneling, host discovery, browser credential theft, lateral movement, and data exfiltration. The activity is assessed as a Russian-speaking, financially motivated cybercrime operation and has been active since at least July 2026.
Post summary
The report details a heap-based buffer overflow in FortiOS/FortiSwitch Manager that is actively exploited in the wild, with a described exploit chain, PivotC2 RAT, and documented infection counts across several countries.