Fortinet Code Execution Vulnerability Exploited by Attackers in PivotC2 RAT Campaigns
Threat actors have been leveraging an unauthenticated remote code execution (RCE) vulnerability in Fortinet systems to deploy a Node.js-based remote access tool, according to SOCRadar.
Threat actors have been leveraging an unauthenticated remote code execution (RCE) vulnerability in Fortinet systems to deploy a Node.js-based remote access tool, according to SOCRadar.
Vulnerability Overview
The flaw, designated CVE-2025-25249 with a CVSS score of 7.4, is a heap overflow vulnerability that was addressed in January through updates for FortiOS and FortiSwitchManager. The vulnerability allows attackers to execute arbitrary code via maliciously crafted requests, as highlighted in Fortinet’s official advisory.
PivotC2 Remote Access Tool
SOCRadar has identified the exploitation of this flaw to distribute the PivotC2 remote access trojan on compromised devices. This post-exploitation tool, associated with FortiGate systems, enables adversaries to establish interactive shell access, route network traffic, conduct reconnaissance, and extract system configurations.
Attack Statistics
The cybersecurity firm suggests that PivotC2 may have been developed using artificial intelligence and has been utilized in attacks since at least July 2026. The campaign targeted over 30,000 IP addresses, resulting in the infection of 178 devices with PivotC2. Most incidents focused on entities in the United States, with at least two instances involving data exfiltration. SOCRadar attributes these activities to a Russian-speaking cybercrime group.
CISA Response
In response, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) included CVE-2025-25249 in its Known Exploited Vulnerabilities (KEV) catalog, mandating federal agencies to apply patches within three days to comply with BOD 26-04. Affected systems must update to FortiOS versions 7.6.4, 7.4.9, 7.2.12, 7.0.18, or later, along with FortiSwitchManager versions 7.2.7 and 7.0.6. All organizations are urged to implement these updates promptly.
Conclusion
The exploitation of this vulnerability underscores the risks of unpatched infrastructure and the evolving tactics of threat actors. The deployment of advanced tools like PivotC2 highlights the need for continuous monitoring and proactive mitigation strategies to prevent unauthorized access and data breaches.
