AI Security AI安全 7h ago Updated 5h ago 更新于 5小时前 43

Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks Fortinet代码执行漏洞在PivotC2 RAT攻击中被利用

CVE-2025-25249 is a high-severity (CVSS 7.4) unauthenticated RCE vulnerability in Fortinet products caused by a heap-based buffer overflow, patched in January 2026 Threat actors are actively exploiting the flaw to deploy PivotC2, a Node.js-based RAT with interactive shell access, traffic tunneling, network scanning, and configuration harvesting capabilities Over 30,000 IP addresses were targeted, resulting in 178 confirmed infections, primarily affecting US entities, with at least two data exfil Fortinet产品存在未认证RCE漏洞CVE-2025-25249(CVSS 7.4),攻击者正利用其部署PivotC2 Node.js RAT 攻击者自2026年7月起利用该漏洞,已扫描超30,000个IP并感染178台设备,主要针对美国实体 CISA已将该漏洞列入已知利用目录,要求联邦机构3天内完成修补,补丁版本已发布 PivotC2后门提供交互式shell、流量隧道、网络扫描和配置窃取能力,疑似由AI辅助开发 攻击者可能是俄罗斯语网络犯罪组织,已导致至少两次数据外泄事件

68
Hot 热度
62
Quality 质量
55
Impact 影响力

Analysis 深度分析

TL;DR

  • CVE-2025-25249 is a high-severity (CVSS 7.4) unauthenticated RCE vulnerability in Fortinet products caused by a heap-based buffer overflow, patched in January 2026
  • Threat actors are actively exploiting the flaw to deploy PivotC2, a Node.js-based RAT with interactive shell access, traffic tunneling, network scanning, and configuration harvesting capabilities
  • Over 30,000 IP addresses were targeted, resulting in 178 confirmed infections, primarily affecting US entities, with at least two data exfiltration incidents
  • SOCRadar believes PivotC2 was likely developed with AI assistance and has been in active use since at least July 2026, possibly by a Russian-speaking cybercrime actor
  • CISA added the vulnerability to its Known Exploited Vulnerabilities catalog, requiring federal agencies to patch within three days under BOD 26-04

Why It Matters

This incident highlights the accelerating trend of AI-assisted malware development, where threat actors leverage generative AI to create more sophisticated and capable remote access trojans. The active exploitation of a previously patched vulnerability underscores the critical importance of rapid patch deployment and continuous vulnerability monitoring for organizations relying on Fortinet infrastructure.

Technical Details

  • Vulnerability: CVE-2025-25249, a heap-based buffer overflow in FortiOS and FortiSwitchManager enabling unauthenticated remote code execution via specially crafted requests (CVSS 7.4)
  • Patched Versions: FortiOS 7.6.4, 7.4.9, 7.2.12, 7.0.18; FortiSwitchManager 7.2.7 and 7.0.6
  • Malware: PivotC2 RAT, a Node.js-based backdoor providing interactive shell access, traffic tunneling, network scanning, and configuration harvesting; likely AI-developed and in use since July 2026
  • Attack Scope: 30,000+ IP addresses scanned, 178 devices infected, primary targeting of US entities with confirmed data exfiltration in at least two cases
  • Response: CISA added CVE-2025-25249 to its KEV catalog with a three-day patch deadline for federal agencies per BOD 26-04

Industry Insight

  • Organizations using Fortinet products must prioritize immediate patching to the specified versions, as active exploitation by threat actors is ongoing and CISA enforcement deadlines are extremely tight
  • The use of AI in developing PivotC2 signals a broader shift toward AI-augmented malware creation, suggesting defenders should expect more sophisticated, rapidly developed threat tools in the future
  • The relatively low infection-to-scan ratio (178 out of 30,000+) indicates that while the attack campaign is targeted rather than broad, the consequences of compromise are severe, reinforcing the need for proactive vulnerability management and network segmentation strategies

TL;DR

  • Fortinet产品存在未认证RCE漏洞CVE-2025-25249(CVSS 7.4),攻击者正利用其部署PivotC2 Node.js RAT
  • 攻击者自2026年7月起利用该漏洞,已扫描超30,000个IP并感染178台设备,主要针对美国实体
  • CISA已将该漏洞列入已知利用目录,要求联邦机构3天内完成修补,补丁版本已发布
  • PivotC2后门提供交互式shell、流量隧道、网络扫描和配置窃取能力,疑似由AI辅助开发
  • 攻击者可能是俄罗斯语网络犯罪组织,已导致至少两次数据外泄事件

为什么值得看

该漏洞已被积极利用且CISA紧急要求3天内修补,对使用Fortinet产品的组织构成直接威胁。同时,攻击者疑似使用AI辅助开发恶意软件,反映了AI在网络安全攻防中的新趋势。

技术解析

  • 漏洞详情:CVE-2025-25249为堆缓冲区溢出漏洞,允许远程未认证攻击者通过特制请求执行任意代码,影响FortiOS和FortiSwitchManager
  • 恶意软件能力:PivotC2 RAT提供交互式shell访问、流量隧道、网络扫描和配置窃取功能,可作为FortiGate后渗透工具使用
  • 补丁版本:FortiOS 7.6.4/7.4.9/7.2.12/7.0.18,FortiSwitchManager 7.2.7/7.0.6
  • 攻击规模:扫描超30,000个IP地址,成功感染178台设备,至少两次入侵导致数据外泄
  • AI关联:SOCRadar认为PivotC2可能使用AI辅助开发,攻击活动自2026年7月起持续

行业启示

  • 紧急响应优先:CISA已将其列入KEV目录并要求3天内修补,所有使用Fortinet产品的组织应立即验证并更新补丁版本
  • AI赋能攻击趋势:攻击者利用AI辅助开发恶意软件,网络安全防御需关注AI在攻防两端的双刃剑效应
  • 供应链安全强化:关键基础设施供应商(如Fortinet)的漏洞影响范围广,需建立快速漏洞响应和补丁验证机制

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全 Research 科学研究