---
schema: 1
kind: vulnerability
title: "CVE-2025-25249 — Fortinet FortiOS/FortiSwitchManager: unauthenticated CAPWAP heap overflow added to CISA KEV, actively exploited since July via the PivotC2 RAT"
headline: "A months-old Fortinet CAPWAP bug reaches CISA KEV alongside an AI-assisted post-exploitation RAT built specifically for FortiGate"
summary: >
  CISA added CVE-2025-25249 to its Known Exploited Vulnerabilities catalog on
  2026-09-09: an unauthenticated heap overflow in the CAPWAP daemon that
  FortiOS and FortiSwitchManager use to manage wireless access points.
  SOCRadar reports a likely Russian-speaking operator has exploited it since
  at least July 2026 against over 30,000 FortiGate IPs, dropping PivotC2, an
  AI-assisted RAT that harvests device credential stores.
discovered_at: "2026-09-10T04:30:00Z"
updated_at: null
event_date: "2026-09-09"
run_id: 2026-09-10T0410Z-intel
priority: high
immediate_action: null
tags: [vulnerabilities, actively-exploited, cisa-kev, rce, pre-auth]
regions: [global]
sectors: [public-sector]
entities: ["product:fortinet-fortios", "malware:pivotc2"]
techniques: [T1190, T1071.001, T1090, T1046, T1552.001, T1021.001, T1059.001, T1055.002, T1027, T1567.002]
affected_products: ["Fortinet FortiOS", "Fortinet FortiSwitchManager", "Fortinet FortiSASE"]
cves:
  - id: CVE-2025-25249
    cvss: "8.1"
    epss: "0.0076"
    type: rce
    vector: zero-click
    auth: pre-auth
    status: [exploited, cisa-kev, patch-available]
    affected: "FortiOS 6.4 (all), 7.0.0-7.0.17, 7.2.0-7.2.11, 7.4.0-7.4.8, 7.6.0-7.6.3; FortiSwitchManager 7.0.0-7.0.5, 7.2.0-7.2.6; FortiSASE 25.1.a.2, 25.2.b"
    fixed: "FortiOS 7.0.18, 7.2.12, 7.4.9, 7.6.4; FortiSwitchManager 7.0.6, 7.2.7 (no confirmed fixed FortiSASE build in sources reached this run)"
sources:
  - url: "https://www.cisa.gov/news-events/alerts/2026/09/09/cisa-adds-four-known-exploited-vulnerabilities-catalog"
    publisher: "CISA"
    date: "2026-09-09"
    role: primary
  - url: "https://socradar.io/blog/cve-2025-25249-pivotc2-fortigate-rat"
    publisher: "SOCRadar (STRU)"
    date: "2026-09-08"
    role: primary
  - url: "https://github.com/advisories/GHSA-mj8x-m8f5-x4w8"
    publisher: "GitHub Advisory Database"
    date: "2026-09-09"
    role: corroborating
  - url: "https://www.sentinelone.com/vulnerability-database/cve-2025-25249/"
    publisher: "SentinelOne"
    date: "2026-01-13"
    role: corroborating
  - url: "https://euvdservices.enisa.europa.eu/api/search?text=CVE-2025-25249"
    publisher: "ENISA EUVD"
    date: "2026-09-10"
    role: corroborating
closed_sources: []
evidence:
  - quote: "The SOCRadar Threat Research Unit (STRU) identified, with high confidence, exploitation of CVE-2025-25249, a heap-based buffer overflow vulnerability in FortiOS and FortiSwitchManager cw_acd daemon."
    publisher: "SOCRadar (STRU)"
  - quote: "Active exploitation has been observed since at least July 2026 and is still ongoing."
    publisher: "SOCRadar (STRU)"
  - quote: "the actors highly likely leveraged AI to develop the RAT"
    publisher: "SOCRadar (STRU)"
verification: multi-source
sourcing_note: "Three different CVSS 3.1 base scores are in circulation for this CVE: NVD's own analyst-assigned score is 9.8, matching SOCRadar's cited figure; the CNA/GHSA-published score (Fortinet PSIRT via GHSA-mj8x-m8f5-x4w8) is 8.1; ENISA EUVD's temporal score is 7.4. The CNA-published 8.1 is used here per the primary-source hierarchy, and the three-way discrepancy is disclosed rather than silently resolved. Fortinet's own PSIRT advisory (FG-IR-25-084) could not be fetched despite three attempted transports; fixed-version data is corroborated instead via SentinelOne's and SOCRadar's citations of that advisory. **Contradiction:** GHSA states affected FortiSASE versions as 25.1.a.2 and 25.2.b; SentinelOne independently states FortiSASE versions 25.1.39 and 25.1.51 — a different version-naming scheme for the same product line neither this entry nor the two sources reconcile. The GHSA-stated FortiSASE versions are recorded as the affected range since GHSA is the CNA-linked record; the SentinelOne figures are disclosed here rather than silently dropped. The exploitation narrative (PivotC2, the 30,000-target/178-infected figures, the Russian-speaking-operator attribution) rests solely on SOCRadar, which sources.json rates reliability C for its own reporting; GHSA and SentinelOne corroborate only the underlying CVE/version facts, not the campaign detail. Reliability set to C to match SOCRadar's own rated reliability rather than the higher-rated corroborating sources, since the substantive narrative is SOCRadar's alone; credibility reflects a single technical assessor with several publishers."
confidence: high
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification:
  reliability: C
  credibility: 2
watchlist_hit: false
actions:
  - "Patch every internet-facing FortiGate/FortiSwitchManager to the fixed builds now, and on any device that exposed CAPWAP (UDP 5246) to an untrusted network before patching, rotate VPN PSKs, SSL-VPN and LDAP bind credentials and admin passwords rather than relying on the patch alone — PivotC2's autonomous mode is built to harvest exactly those credential stores."
updates: []
migrated_from: null
---

CISA added CVE-2025-25249 to its Known Exploited Vulnerabilities catalog on 2026-09-09: a heap-based buffer overflow in the `cw_acd` CAPWAP daemon that FortiOS and FortiSwitchManager use to manage wireless access points, listening unauthenticated on UDP 5246 ([CISA, 2026-09-09](https://www.cisa.gov/news-events/alerts/2026/09/09/cisa-adds-four-known-exploited-vulnerabilities-catalog)). SOCRadar's Threat Research Unit reports, with high confidence, that a likely Russian-speaking financially motivated operator has exploited the flaw since at least July 2026, targeting more than 30,000 FortiGate IP addresses and infecting 178 devices ([SOCRadar, 2026-09-08](https://socradar.io/blog/cve-2025-25249-pivotc2-fortigate-rat)). The exploit fingerprints a target's CAPWAP Discovery Response to leak memory pointers and defeat ASLR, matches the reported hardware/software revision against a hardcoded table of thirteen FortiGate and two FortiAP models on FortiOS 7.4.0-7.4.8, then grooms and overflows the daemon's heap-chunk pool via crafted CAPWAP messages to redirect execution ([SOCRadar, 2026-09-08](https://socradar.io/blog/cve-2025-25249-pivotc2-fortigate-rat)). Successful exploitation drops PivotC2, an AI-assisted Node.js RAT purpose-built for FortiGate post-exploitation that maintains a persistent multiplexed TLS channel, supports interactive shells and SOCKS5/HTTP tunneling, and — via an autonomous mode — harvests FortiGate configuration files and encrypted credential stores (VPN PSKs, SSL-VPN and LDAP bind credentials, admin accounts) using a device-specific key pulled from the device's own sync file ([SOCRadar, 2026-09-08](https://socradar.io/blog/cve-2025-25249-pivotc2-fortigate-rat)). In two confirmed US intrusions, operators pivoted further with reverse-SSH relays, network scanning, RDP-enablement registry edits for pass-the-hash, a PowerShell script that downloads and XOR-decrypts a payload before injecting it into `svchost.exe` via `OpenProcess`/`VirtualAllocEx`/`WriteProcessMemory`, and Exchange mailbox exfiltration to attacker-controlled cloud storage ([SOCRadar, 2026-09-08](https://socradar.io/blog/cve-2025-25249-pivotc2-fortigate-rat)). Affected: FortiOS 6.4 through 7.6.3, FortiSwitchManager 7.0-7.2.6, and FortiSASE 25.1.a.2/25.2.b; fixed in FortiOS 7.6.4/7.4.9/7.2.12/7.0.18 and FortiSwitchManager 7.2.7/7.0.6, with no confirmed fixed FortiSASE build in the sources reached this run.

**Defender takeaway:** any FortiGate that exposed CAPWAP to the internet or an untrusted network segment before patching should be treated as a potential credential-harvesting target, not only a code-execution target — rotate VPN PSKs, SSL-VPN and LDAP bind credentials and admin passwords on affected devices rather than relying on the patch alone.

**Triage:** an unexplained outbound TLS connection from a FortiGate management interface to a non-Fortinet destination, sustained over hours with periodic small keepalive-sized packets, is the multiplexed C2 channel's signature; normal FortiGate outbound traffic is FortiGuard update/telemetry to Fortinet's own infrastructure, not a persistent operator-controlled tunnel.
