CTIPilot

Fortinet FortiOS/FortiSwitchManager CAPWAP heap overflow, CISA KEV 2026-09-09, actively exploited since July 2026 via the PivotC2 RAT

cve · CVE-2025-25249

Coverage timeline
1
first 2026-09-10 → last 2026-09-10
Peak priority
high
1 high
Sources cited
5
5 hosts
Sections touched
1
trending-vulnerabilities
Co-occurring entities
4
see Co-occurring entities below
ATT&CK techniques
10
pinned v19.2 · see below

ATT&CK techniques

10 techniques observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-09-10/cve-2025-25249-fortinet-fortios-capwap-pivotc2-rat · ATT&CK page ↗

Execution TA0002

T1059.001Command and Scripting Interpreter: PowerShell×1

Adversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system. Adversaries can use PowerShell to perform a number of actions, including discovery of information and execution of code. Examples include the <code>Start-Process</code> cmdlet which can be used to run an executable and the <code>Invoke-Command</code> cmdlet which runs a command locally or on a remote computer (though administrator permissions are required to use PowerShell to connect to remote systems).

Evidence: 2026-09-10/cve-2025-25249-fortinet-fortios-capwap-pivotc2-rat · ATT&CK page ↗

Privilege Escalation TA0004

T1055.002Process Injection: Portable Executable Injection×1

Adversaries may inject portable executables (PE) into processes in order to evade process-based defenses as well as possibly elevate privileges. PE injection is a method of executing arbitrary code in the address space of a separate live process.

Evidence: 2026-09-10/cve-2025-25249-fortinet-fortios-capwap-pivotc2-rat · ATT&CK page ↗

Stealth TA0005

T1027Obfuscated Files or Information×1

Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses.

Evidence: 2026-09-10/cve-2025-25249-fortinet-fortios-capwap-pivotc2-rat · ATT&CK page ↗

T1055.002Process Injection: Portable Executable Injection×1

Adversaries may inject portable executables (PE) into processes in order to evade process-based defenses as well as possibly elevate privileges. PE injection is a method of executing arbitrary code in the address space of a separate live process.

Evidence: 2026-09-10/cve-2025-25249-fortinet-fortios-capwap-pivotc2-rat · ATT&CK page ↗

Credential Access TA0006

T1552.001Unsecured Credentials: Credentials In Files×1

Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords.

Evidence: 2026-09-10/cve-2025-25249-fortinet-fortios-capwap-pivotc2-rat · ATT&CK page ↗

Discovery TA0007

T1046Network Service Discovery×1

Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation. Common methods to acquire this information include port, vulnerability, and/or wordlist scans using tools that are brought onto a system.

Evidence: 2026-09-10/cve-2025-25249-fortinet-fortios-capwap-pivotc2-rat · ATT&CK page ↗

Lateral Movement TA0008

T1021.001Remote Services: Remote Desktop Protocol×1

Adversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP). The adversary may then perform actions as the logged-on user.

Evidence: 2026-09-10/cve-2025-25249-fortinet-fortios-capwap-pivotc2-rat · ATT&CK page ↗

Command and Control TA0011

T1071.001Application Layer Protocol: Web Protocols×1

Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

Evidence: 2026-09-10/cve-2025-25249-fortinet-fortios-capwap-pivotc2-rat · ATT&CK page ↗

T1090Proxy×1

Adversaries may use a connection proxy to direct network traffic between systems or act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use these types of proxies to manage command and control communications, reduce the number of simultaneous outbound network connections, provide resiliency in the face of connection loss, or to ride over existing trusted communications paths between victims to avoid suspicion. Adversaries may chain together multiple proxies to further disguise the source of malicious traffic.

Evidence: 2026-09-10/cve-2025-25249-fortinet-fortios-capwap-pivotc2-rat · ATT&CK page ↗

Exfiltration TA0010

T1567.002Exfiltration Over Web Service: Exfiltration to Cloud Storage×1

Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel. Cloud storage services allow for the storage, edit, and retrieval of data from a remote cloud storage server over the Internet.

Evidence: 2026-09-10/cve-2025-25249-fortinet-fortios-capwap-pivotc2-rat · ATT&CK page ↗

Story timeline

  1. 2026-09-10CVE-2025-25249, Fortinet FortiOS/FortiSwitchManager: unauthenticated CAPWAP heap overflow added to CISA KEV, actively exploited since July via the PivotC2 RAT
    trending-vulnerabilitiesA months-old Fortinet CAPWAP bug reaches CISA KEV alongside an AI-assisted post-exploitation RAT built specifically for FortiGate

Where this entity is cited

  • trending-vulnerabilities1

Source distribution

  • cisa.gov1 (20%)
  • euvdservices.enisa.europa.eu1 (20%)
  • github.com1 (20%)
  • sentinelone.com1 (20%)
  • socradar.io1 (20%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Fortinet FortiOS/FortiSwitchManager CAPWAP heap overflow, CISA KEV 2026-09-09, actively exploited since July 2026 via the PivotC2 RAT (1)

2026-09-10 · view entry permalink →

HIGHCVE-2025-25249exploitedNATOC2

CVE-2025-25249, Fortinet FortiOS/FortiSwitchManager: unauthenticated CAPWAP heap overflow added to CISA KEV, actively exploited since July via the PivotC2 RAT

CISA added CVE-2025-25249 to its Known Exploited Vulnerabilities catalog on 2026-09-09: a heap-based buffer overflow in the cw_acd CAPWAP daemon that FortiOS and FortiSwitchManager use to manage wireless access points, listening unauthenticated on UDP 5246 (CISA, 2026-09-09). SOCRadar's Threat Research Unit reports, with high confidence, that a likely Russian-speaking financially motivated operator has exploited the flaw since at least July 2026, targeting more than 30,000 FortiGate IP addresses and infecting 178 devices (SOCRadar, 2026-09-08). The exploit fingerprints a target's CAPWAP Discovery Response to leak memory pointers and defeat ASLR, matches the reported hardware/software revision against a hardcoded table of thirteen FortiGate and two FortiAP models on FortiOS 7.4.0-7.4.8, then grooms and overflows the daemon's heap-chunk pool via crafted CAPWAP messages to redirect execution (SOCRadar, 2026-09-08). Successful exploitation drops PivotC2, an AI-assisted Node.js RAT purpose-built for FortiGate post-exploitation that maintains a persistent multiplexed TLS channel, supports interactive shells and SOCKS5/HTTP tunneling, and (via an autonomous mode) harvests FortiGate configuration files and encrypted credential stores (VPN PSKs, SSL-VPN and LDAP bind credentials, admin accounts) using a device-specific key pulled from the device's own sync file (SOCRadar, 2026-09-08). In two confirmed US intrusions, operators pivoted further with reverse-SSH relays, network scanning, RDP-enablement registry edits for pass-the-hash, a PowerShell script that downloads and XOR-decrypts a payload before injecting it into svchost.exe via OpenProcess/VirtualAllocEx/WriteProcessMemory, and Exchange mailbox exfiltration to attacker-controlled cloud storage (SOCRadar, 2026-09-08). Affected: FortiOS 6.4 through 7.6.3, FortiSwitchManager 7.0-7.2.6, and FortiSASE 25.1.a.2/25.2.b; fixed in FortiOS 7.6.4/7.4.9/7.2.12/7.0.18 and FortiSwitchManager 7.2.7/7.0.6, with no confirmed fixed FortiSASE build in the sources reached this run.

Triage: an unexplained outbound TLS connection from a FortiGate management interface to a non-Fortinet destination, sustained over hours with periodic small keepalive-sized packets, is the multiplexed C2 channel's signature; normal FortiGate outbound traffic is FortiGuard update/telemetry to Fortinet's own infrastructure, not a persistent operator-controlled tunnel.

The SOCRadar Threat Research Unit (STRU) identified, with high confidence, exploitation of CVE-2025-25249, a heap-based buffer overflow vulnerability in FortiOS and FortiSwitchManager cw_acd daemon.

Active exploitation has been observed since at least July 2026 and is still ongoing.

the actors highly likely leveraged AI to develop the RAT

SOCRadar (STRU) 2026-09-08
vulnerability10 Sep 04:30Zmulti-sourceOpen finding ↗