PivotC2: CVE-2025-25249 FortiGate CAPWAP RCE delivers Node.js RAT (178 victims)
SOCRadar Threat Research (covered 10 September 2026 by SecurityWeek) reports active exploitation of CVE-2025-25249, a heap-based buffer overflow in the FortiOS / FortiSwitchManager cw_acd CAPWAP daemon (UDP 5246), delivering PivotC2 — a Node.js post-exploitation RAT for FortiGate with interactive shell, tunneling, scanning and config/credential harvesting. SOCRadar cites NVD CVSSv3 9.8; Fortinet advisory FG-IR-25-084. Exploitation observed since at least July 2026; ~30k targeted IPs and 178 confirmed PivotC2 sessions (majority US; two full US intrusions with data theft). Tradecraft assessed as Russian-speaking cybercrime; RAT comments suggest AI-assisted development. Affected examples: FortiOS 7.6.0–7.6.3, 7.4.0–7.4.8, 7.2.0–7.2.11, 7.0.0–7.0.17; FortiSwitchManager 7.2.0–7.2.6 and 7.0.0–7.0.5. Fixed: FortiOS 7.6.4 / 7.4.9 / 7.2.12 / 7.0.18; FortiSwitchManager 7.2.7 / 7.0.6. Distinct from desk card fortinet-fortimonitoronsight-20260909. Primary: SOCRadar; vendor: FG-IR-25-084; wire: SecurityWeek.
- Product
- Fortinet FortiOS; FortiSwitchManager (cw_acd / CAPWAP)
- Versions
- FortiOS 7.6.0–7.6.3, 7.4.0–7.4.8, 7.2.0–7.2.11, 7.0.0–7.0.17; FortiSwitchManager 7.2.0–7.2.6, 7.0.0–7.0.5; fixed FortiOS 7.6.4/7.4.9/7.2.12/7.0.18; FSM 7.2.7/7.0.6
- CVSS
- 9.8 (NVD CVSSv3 per SOCRadar)
- Exploited in Australia?
- unknown
- Patch to
- Upgrade FortiOS/FortiSwitchManager to fixed builds in FG-IR-25-084; hunt CAPWAP/Node.js PivotC2 IoCs and C2 sessions
Primary: SOCRadar — PivotC2 / CVE-2025-25249 · Vendor: Fortinet FG-IR-25-084 · CVE: CVE-2025-25249 · SecurityWeek (10 Sep 2026)
