Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks
CVE-2025-25249 is a high-severity (CVSS 7.4) unauthenticated RCE vulnerability in Fortinet products caused by a heap-based buffer overflow, patched in January 2026 Threat actors are actively exploiting the flaw to deploy PivotC2, a Node.js-based RAT with interactive shell access, traffic tunneling, network scanning, and configuration harvesting capabilities Over 30,000 IP addresses were targeted, resulting in 178 confirmed infections, primarily affecting US entities, with at least two data exfil
Analysis
TL;DR
- CVE-2025-25249 is a high-severity (CVSS 7.4) unauthenticated RCE vulnerability in Fortinet products caused by a heap-based buffer overflow, patched in January 2026
- Threat actors are actively exploiting the flaw to deploy PivotC2, a Node.js-based RAT with interactive shell access, traffic tunneling, network scanning, and configuration harvesting capabilities
- Over 30,000 IP addresses were targeted, resulting in 178 confirmed infections, primarily affecting US entities, with at least two data exfiltration incidents
- SOCRadar believes PivotC2 was likely developed with AI assistance and has been in active use since at least July 2026, possibly by a Russian-speaking cybercrime actor
- CISA added the vulnerability to its Known Exploited Vulnerabilities catalog, requiring federal agencies to patch within three days under BOD 26-04
Why It Matters
This incident highlights the accelerating trend of AI-assisted malware development, where threat actors leverage generative AI to create more sophisticated and capable remote access trojans. The active exploitation of a previously patched vulnerability underscores the critical importance of rapid patch deployment and continuous vulnerability monitoring for organizations relying on Fortinet infrastructure.
Technical Details
- Vulnerability: CVE-2025-25249, a heap-based buffer overflow in FortiOS and FortiSwitchManager enabling unauthenticated remote code execution via specially crafted requests (CVSS 7.4)
- Patched Versions: FortiOS 7.6.4, 7.4.9, 7.2.12, 7.0.18; FortiSwitchManager 7.2.7 and 7.0.6
- Malware: PivotC2 RAT, a Node.js-based backdoor providing interactive shell access, traffic tunneling, network scanning, and configuration harvesting; likely AI-developed and in use since July 2026
- Attack Scope: 30,000+ IP addresses scanned, 178 devices infected, primary targeting of US entities with confirmed data exfiltration in at least two cases
- Response: CISA added CVE-2025-25249 to its KEV catalog with a three-day patch deadline for federal agencies per BOD 26-04
Industry Insight
- Organizations using Fortinet products must prioritize immediate patching to the specified versions, as active exploitation by threat actors is ongoing and CISA enforcement deadlines are extremely tight
- The use of AI in developing PivotC2 signals a broader shift toward AI-augmented malware creation, suggesting defenders should expect more sophisticated, rapidly developed threat tools in the future
- The relatively low infection-to-scan ratio (178 out of 30,000+) indicates that while the attack campaign is targeted rather than broad, the consequences of compromise are severe, reinforcing the need for proactive vulnerability management and network segmentation strategies
Disclaimer: The above content is generated by AI and is for reference only.