CTIPilot
← Back to the live brief
HIGHCVE-2025-25249exploitedNATOC2vulnerability

CVE-2025-25249, Fortinet FortiOS/FortiSwitchManager: unauthenticated CAPWAP heap overflow added to CISA KEV, actively exploited since July via the PivotC2 RAT

A months-old Fortinet CAPWAP bug reaches CISA KEV alongside an AI-assisted post-exploitation RAT built specifically for FortiGate

Defender actions

  • Patch every internet-facing FortiGate/FortiSwitchManager to the fixed builds now, and on any device that exposed CAPWAP (UDP 5246) to an untrusted network before patching, rotate VPN PSKs, SSL-VPN and LDAP bind credentials and admin passwords rather than relying on the patch alone; PivotC2's autonomous mode is built to harvest exactly those credential stores.

Analysis

CISA added CVE-2025-25249 to its Known Exploited Vulnerabilities catalog on 2026-09-09: a heap-based buffer overflow in the cw_acd CAPWAP daemon that FortiOS and FortiSwitchManager use to manage wireless access points, listening unauthenticated on UDP 5246 (CISA, 2026-09-09). SOCRadar's Threat Research Unit reports, with high confidence, that a likely Russian-speaking financially motivated operator has exploited the flaw since at least July 2026, targeting more than 30,000 FortiGate IP addresses and infecting 178 devices (SOCRadar, 2026-09-08). The exploit fingerprints a target's CAPWAP Discovery Response to leak memory pointers and defeat ASLR, matches the reported hardware/software revision against a hardcoded table of thirteen FortiGate and two FortiAP models on FortiOS 7.4.0-7.4.8, then grooms and overflows the daemon's heap-chunk pool via crafted CAPWAP messages to redirect execution (SOCRadar, 2026-09-08). Successful exploitation drops PivotC2, an AI-assisted Node.js RAT purpose-built for FortiGate post-exploitation that maintains a persistent multiplexed TLS channel, supports interactive shells and SOCKS5/HTTP tunneling, and (via an autonomous mode) harvests FortiGate configuration files and encrypted credential stores (VPN PSKs, SSL-VPN and LDAP bind credentials, admin accounts) using a device-specific key pulled from the device's own sync file (SOCRadar, 2026-09-08). In two confirmed US intrusions, operators pivoted further with reverse-SSH relays, network scanning, RDP-enablement registry edits for pass-the-hash, a PowerShell script that downloads and XOR-decrypts a payload before injecting it into svchost.exe via OpenProcess/VirtualAllocEx/WriteProcessMemory, and Exchange mailbox exfiltration to attacker-controlled cloud storage (SOCRadar, 2026-09-08). Affected: FortiOS 6.4 through 7.6.3, FortiSwitchManager 7.0-7.2.6, and FortiSASE 25.1.a.2/25.2.b; fixed in FortiOS 7.6.4/7.4.9/7.2.12/7.0.18 and FortiSwitchManager 7.2.7/7.0.6, with no confirmed fixed FortiSASE build in the sources reached this run.

Triage: an unexplained outbound TLS connection from a FortiGate management interface to a non-Fortinet destination, sustained over hours with periodic small keepalive-sized packets, is the multiplexed C2 channel's signature; normal FortiGate outbound traffic is FortiGuard update/telemetry to Fortinet's own infrastructure, not a persistent operator-controlled tunnel.

Cited evidence

The SOCRadar Threat Research Unit (STRU) identified, with high confidence, exploitation of CVE-2025-25249, a heap-based buffer overflow vulnerability in FortiOS and FortiSwitchManager cw_acd daemon.

Active exploitation has been observed since at least July 2026 and is still ongoing.

the actors highly likely leveraged AI to develop the RAT

SOCRadar (STRU) 2026-09-08

Sources5

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.