CVE-2025-25249 (CVSS 9.8): Fortinet FortiOS CAPWAP Zero-Day Weaponised by PivotC2 RAT — 178 Firewalls Compromised and Counting
Your perimeter firewall just became the breach point. On September 9, 2026, CISA added CVE-2025-25249 to its Known Exploited Vulnerabilities catalog — a CVSS 9.8 Critical heap-based buffer overflow buried deep in Fortinet’s FortiOS CAPWAP daemon. Attackers require no credentials, no click, no prior access to execute arbitrary code on your FortiGate. A suspected Russian-speaking cybercrime group has already exploited this to plant the PivotC2 RAT on 178 internet-facing firewalls, scanning the interior of each victim’s network for Exchange servers, Active Directory, and storage infrastructure. If your FortiGate is running any version from FortiOS 6.4 through 7.6.3 and faces the public internet on UDP/5246, the clock is running.
- CVE-2025-25249 is a heap-based buffer overflow in FortiOS’s
cw_acddaemon (CAPWAP, UDP/5246) — unauthenticated, no user interaction. - CVSS v3 score: 9.8 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
- Active exploitation confirmed since at least July 2026; CISA KEV listed September 9, 2026.
- PivotC2 RAT is a Node.js implant providing shells, SOCKS5 tunnels, port scans, and AES credential decryption — all from inside your firewall.
- 178 FortiGate devices confirmed compromised across 30,000+ targeted IPs; two full network intrusions with data exfiltration.
- Patch to FortiOS 7.6.4 / 7.4.9 / 7.2.12 / 7.0.18 (and FortiSwitchManager 7.2.7 / 7.0.6) immediately.
- Interim workaround: block inbound UDP 5246–5249 at the border if an immediate upgrade is not possible.
What Is CVE-2025-25249 and Why Is It So Dangerous?
Disclosed in Fortinet advisory FG-IR-25-084 on January 13, 2026, CVE-2025-25249 is a heap-based buffer overflow in the cw_acd (Control and Provisioning of Wireless Access Points daemon) component of FortiOS and FortiSwitchManager. CAPWAP is the protocol FortiGate uses to manage FortiAP wireless access points. It listens on UDP port 5246 — and by default this service is reachable on management interfaces that may also face the internet.
What makes this vulnerability exceptionally dangerous is its zero-interaction profile: an attacker on the same network segment — or more critically, on the internet if UDP/5246 is exposed — can send a single specially crafted CAPWAP packet and overwrite adjacent heap memory. No authentication. No account. No phishing campaign required. The attack vector is Network (AV:N), complexity is Low (AC:L), and no privileges are required (PR:N), yielding the near-maximum CVSS score of 9.8.
The breadth of exposure is staggering. Affected versions span every major FortiOS branch released over the past four years:
| Product | Vulnerable Versions | Fixed Version |
|---|---|---|
| FortiOS | 7.6.0 – 7.6.3 | 7.6.4+ |
| FortiOS | 7.4.0 – 7.4.8 | 7.4.9+ |
| FortiOS | 7.2.0 – 7.2.11 | 7.2.12+ |
| FortiOS | 7.0.0 – 7.0.17 | 7.0.18+ |
| FortiOS | 6.4 (all) | Upgrade to 7.0.18+ |
| FortiSwitchManager | 7.2.0 – 7.2.6 | 7.2.7+ |
| FortiSwitchManager | 7.0.0 – 7.0.5 | 7.0.6+ |
Inside the Exploit: How the CAPWAP Attack Chain Works
Researchers reverse-engineered the weaponised exploit and found it operates in three stages. First, the attacker sends a discovery packet to UDP/5246 to leak heap layout information — effectively defeating ASLR. Second, a custom binary called fortirun.bin performs heap grooming to align memory in a predictable state, then sends the malformed CAPWAP packet that corrupts a doubly-linked list pointer. This delivers a write-what-where primitive that redirects code execution to attacker-controlled shellcode. Third, the shellcode drops a Node.js stager that phones home to the PivotC2 command-and-control infrastructure.
The entire chain runs pre-authentication against the CAPWAP port. For organisations that have disabled FortiAP management but never restricted CAPWAP at the local-in policy layer, the port remains open and the daemon remains reachable — an invisible attack surface that most firewall audits miss entirely. If you have conducted a firewall policy audit recently, now is the moment to verify whether local-in policies explicitly drop inbound UDP/5246–5249 on all external interfaces.
Meet PivotC2: The FortiGate RAT Living Inside Your Firewall
PivotC2 is not a generic commodity backdoor. It is a purpose-built FortiGate post-exploitation framework, assessed by SOCRadar to have been developed with AI assistance — and the sophistication shows. Once deployed inside a compromised FortiGate, it delivers:
- Interactive shell & command execution — full OS-level access to the firewall’s Linux subsystem.
- SOCKS5 and HTTP proxy tunnels with port forwarding — the firewall becomes an internal pivot point, routing attacker traffic deep into your LAN, bypassing NAT and network segmentation controls.
- CIDR-range port scanning targeting ports 22, 80, 389, 443, 445, 902, 1433, 3389, and 5432 — mapping out every SSH, web, LDAP, SMB, VMware, MSSQL, RDP, and PostgreSQL service on the internal network.
- FortiGate configuration harvesting with AES credential decryption — both AES-256-CBC and AES-128-GCM variants are cracked automatically, exposing admin passwords, SSL-VPN credentials, LDAP bind passwords, and IPsec PSKs in plaintext.
- Autonomous “auto-mode” operation — the RAT can execute recon and credential-harvesting routines with zero operator interaction, meaning the threat actor can sleep while your environment is mapped.
- File operations — upload, download, directory listing, and deletion.
C2 communications egress via obfs4proxy-obfuscated Tor circuits, making outbound detection difficult. Known C2 IP addresses include 146.103.99.177 and 46.151.29.58 — your SOC team should hunt for these in firewall logs and DNS query history.
Who Is Behind the Attacks?
SOCRadar’s threat intelligence team attributes this campaign with high confidence to a Russian-speaking, financially motivated cybercrime operation. The evidence is circumstantial but multi-faceted: Russian-language comments embedded in the PivotC2 source code, post-exploitation tradecraft focused on Exchange mailboxes and object-storage infrastructure (consistent with Business Email Compromise monetisation or ransomware staging), and a broad multi-vulnerability interest spanning CVE-2024-47575 (FortiJump) and CVE-2024-26304 (FortiOS earlier RCE). The group also shows cross-tool overlap with prior FortiGate exploitation campaigns.
Financially motivated actors do not discriminate by geography. Two confirmed full network intrusions with data exfiltration have been documented in US organisations, and the 30,000+ IP targeting suggests a global mass-exploitation approach — not a targeted campaign. Indian enterprises running FortiGate on internet-facing segments should treat this as a direct threat, not a western-market problem.
What You Should Do Right Now — Sanjay Seth’s Expert Recommendations
Having architected and secured FortiGate deployments for enterprises across India for over three decades, here is the exact response playbook I would execute for any affected organisation:
- Patch immediately. Log in to the Fortinet Support Portal and upgrade to the fixed version for your branch (see table above). Do not wait for a maintenance window — schedule an emergency change. FortiOS upgrades on most appliances take under 10 minutes with a clean config backup in place.
-
If patching is delayed, apply the interim workaround. Create a local-in policy on all external-facing interfaces to drop inbound UDP/5246–5249. On FortiOS:
config firewall local-in-policy → edit 0 → set intf <wan-intf> → set srcaddr all → set dstaddr all → set action deny → set service CAPWAP → set schedule always → end. Verify withdiagnose firewall packet locate. -
Audit your CAPWAP exposure. Run
get system interfaceand check whether any interface hasallowaccessincluding CAPWAP on an external-facing or DMZ interface. If you do not use FortiAP, disable the service entirely:config system interface → edit <intf> → unset allowaccess capwap → end. -
Hunt for PivotC2 indicators. Search for the file
/tmp/.i.js, unexpected Node.js processes (rundiagnose sys top), and outbound connections to 146.103.99.177 or 46.151.29.58 in your FortiGate traffic logs. - If indicators are found, assume full compromise. PivotC2 harvests and decrypts all stored credentials. Rotate every credential associated with this firewall: admin passwords, SSL-VPN user passwords, LDAP bind passwords, RADIUS secrets, IPsec PSKs, and any API tokens. FortiGate is typically the single device that “knows” all your network secrets — a compromised FortiGate is a compromised domain.
- Enable FortiGate’s Security Fabric to correlate anomalous lateral movement IoCs — PivotC2’s internal port scans will generate detectable flows in FortiAnalyzer. If you do not have centralised logging and threat correlation today, this incident is the business case to build it. A zero-trust network architecture would contain an exploited perimeter device: if your flat network relies solely on the FortiGate perimeter for internal segmentation, lateral movement from a compromised firewall is essentially unimpeded.
India Context: Why This Matters for Your Organisation
Fortinet commands a significant share of the Indian enterprise firewall market — FortiGate appliances protect networks in BFSI, healthcare, manufacturing, IT/ITeS, and government organisations nationwide. Many of these deployments run FortiOS 7.2.x or 7.0.x branches for stability reasons, placing them squarely in the vulnerable range. India’s CERT-In Directions 2022 require reporting of “critical system vulnerabilities and their exploitation” within six hours of detection — an active PivotC2 infection on a perimeter firewall would almost certainly meet this threshold. SEBI-regulated entities operating under CSCRF 2024 face additional requirements to demonstrate compensating controls for critical infrastructure vulnerabilities.
Organisations that have not yet aligned with a structured vulnerability management programme should note that CVE-2025-25249 was publicly disclosed in January 2026 with a CVSS 9.8 rating. Eight months elapsed between disclosure and CISA’s KEV listing — time during which attackers quietly built and deployed the PivotC2 campaign. A mature vulnerability management practice would have prioritised patching a CVSS 9.8 No-Auth Network RCE within days of disclosure, long before exploitation began.
Frequently Asked Questions
My FortiGate does not use FortiAP wireless controllers — am I still at risk?
Yes. The cw_acd daemon runs by default in FortiOS regardless of whether you have any FortiAP devices deployed. CAPWAP listeners are active on management interfaces unless explicitly disabled. Run get system interface | grep capwap to check your exposure. If CAPWAP appears in the allowaccess field on any internet-facing interface, apply the local-in policy workaround immediately.
I applied the Fortinet patch in January 2026 — do I need to do anything else?
If you patched to the fixed versions listed above and your CAPWAP service was not exposed to the internet in the interim, your risk is low. However, verify your current running version with get system status and confirm the exact build number matches a fixed release. Also run the PivotC2 IoC hunt (check for /tmp/.i.js and unexpected Node.js processes) as a precaution — exploitation began as early as July 2026, and some patches were applied but PivotC2 persistence mechanisms survived the upgrade.
How does the CISA KEV listing affect Indian organisations?
CISA’s KEV catalog is a US federal mandate, but it serves a critical function for global security teams: it confirms a vulnerability is actively exploited in the real world, not merely theoretically dangerous. CERT-In advisories frequently cite KEV additions. Indian enterprises should treat a KEV listing as a near-immediate patch mandate. The fact that this was listed on September 9, 2026 and exploitation has been confirmed since July means attackers have a two-month head start on defenders who are only acting now.
Should I be concerned about data already exfiltrated from a potentially compromised device?
If forensic analysis reveals any PivotC2 IoC — the /tmp/.i.js file, a Node.js process, connections to the known C2 IPs — assume the worst. PivotC2’s automated credential decryption means your FortiGate’s configuration file has been parsed and every recoverable credential exfiltrated. This includes SSL-VPN user databases (potentially thousands of employee credentials), LDAP/AD bind passwords, and any other secrets stored in the firewall config. A full incident response engagement is warranted, including notification to affected users and review of your CERT-In disclosure obligations.
The window to act is narrow. CVE-2025-25249 has been exploited in the wild for months, 178 firewalls are already reporting to an attacker’s command server, and the PivotC2 RAT is sophisticated enough to operate autonomously inside your network without triggering a single alert on an unmonitored perimeter device. Patching FortiOS is step one. Verifying your local-in policies, hunting for IoCs, and building the monitoring and segmentation that makes exploitation survivable — that is the deeper work.
If you run FortiGate in your organisation and are uncertain about your exposure, patch status, or whether your network logging would even detect a PivotC2 infection, let’s talk. Reach out for a no-obligation security assessment — I have spent three decades hardening FortiGate deployments across India’s most demanding environments, and I can help you determine whether CVE-2025-25249 represents an active gap in your defences or a closed chapter in your patch history.