FortiGate Malware Exploits Critical Firewall Flaw

Active exploitation of FortiGate CVE-2025-25249 to deploy custom Node.js RAT

An active FortiGate malware campaign is exploiting a critical vulnerability to compromise internet-facing firewall appliances. Attackers are deploying a custom Node.js remote access trojan called PivotC2, which can steal credentials, transfer files and provide a foothold into protected networks.

FortiGate malware campaign targets CVE-2025-25249

SOCRadar’s Threat Research Unit reported the activity on 8 September 2026, assessing with high confidence that threat actors are actively exploiting CVE-2025-25249. The vulnerability affects the cw_acd daemon used by FortiOS and FortiSwitchManager.

CVE-2025-25249 is a heap-based buffer overflow with a CVSS v3 score of 9.8. A remote attacker does not need to authenticate before exploiting it. Instead, specially crafted requests sent to the vulnerable service can trigger memory corruption and allow arbitrary code execution.

The vulnerable daemon supports the Control and Provisioning of Wireless Access Points protocol, commonly known as CAPWAP. Fortinet uses CAPWAP to manage wireless access points centrally, and its control service listens on UDP port 5246. This can expose the vulnerable component on FortiGate appliances reachable from the internet.

Affected Fortinet products and versions

The reported affected product range covers FortiOS 6.4 through FortiOS 7.6.3. FortiSwitchManager releases in the 7.0.x and 7.2.x branches are also affected by the underlying vulnerability.

Fortinet issued patches following the vulnerability’s disclosure on 13 January 2026. Despite those updates being available, the newly reported FortiGate malware activity shows that attackers are still finding vulnerable appliances months after disclosure.

Organisations are particularly exposed where UDP port 5246 is accessible from untrusted networks and an affected, unpatched release is running. FortiSwitchManager users must also address the flaw, although the observed PivotC2 deployment described by researchers is specifically designed for FortiGate appliances.

How attackers install PivotC2 on FortiGate

The attackers are not relying solely on a public, off-the-shelf exploitation framework. Researchers identified a custom binary named fortirun.bin, supported by Bash and Python automation scripts that repeatedly attempt exploitation against selected IP addresses until they succeed.

When the heap-based buffer overflow is triggered successfully, the exploit opens a reverse shell from the compromised appliance. It then executes a one-line JavaScript stager through Node.js, beginning a multistage process that retrieves and launches the main FortiGate malware payload.

The JavaScript stager connects to infrastructure controlled by the attacker and downloads an encoded second-stage payload. It decodes the content from Base64, applies XOR decryption and writes the resulting malware to a temporary file on the appliance.

The payload is launched as a detached background process. This means it can continue operating after the initial exploitation connection and reverse shell have closed, giving the attacker a more durable remote foothold than the original exploit session alone.

PivotC2 creates an encrypted command channel

The second-stage payload is PivotC2, a purpose-built Node.js post-exploitation framework. The recovered sample identifies itself as version 0.2.3, suggesting that the software remains under active development rather than representing a finished, static tool.

SOCRadar researchers also observed detailed inline comments and structured usage guidance in the recovered code. They assessed that these characteristics strongly suggest the developers used AI-assisted coding during its creation, although that observation does not identify the person or group responsible.

PivotC2 operates as a lightweight remote access tool with behaviour resembling SSH. Rather than waiting for an attacker to connect through an inbound firewall rule, it initiates an outbound TLS connection from the compromised FortiGate to its command and control server.

This approach helps the FortiGate malware avoid restrictions that would block unsolicited inbound connections. Once established, the encrypted connection carries multiple forms of attacker traffic through one socket using a binary framing protocol.

The framework can multiplex several communication channels over that connection. Its supported capabilities include:

  • Opening interactive command shells on the compromised appliance.
  • Uploading files to the FortiGate and downloading files from it.
  • Creating SOCKS5 and HTTP proxy tunnels for relaying traffic.
  • Establishing local and remote port forwarding connections.
  • Collecting FortiGate configuration and network interface information.

These functions allow an operator to control the appliance, move data and potentially use it as a pivot point. Proxy tunnelling and port forwarding are especially significant because a perimeter firewall is positioned between external systems and internal network resources.

FortiGate malware extracts protected credentials

PivotC2 is more than a general remote administration utility. It contains functionality tailored to FortiGate systems, including the ability to collect device configuration files and enumerate network interface data.

The malware can also process encrypted credential fields marked as ENC in FortiGate data. Researchers found AES-256-CBC and AES-128-GCM decryption routines intended to recover protected values in plaintext.

According to the analysis, the information exposed through these routines can include:

  • VPN pre-shared keys.
  • SSL-VPN credentials.
  • Wireless network passwords.
  • FortiGate administrator account credentials.

This credential extraction capability increases the consequences of a successful compromise. Even if the malware is removed from the firewall, credentials obtained from its configuration could remain useful for accessing VPN services, wireless networks, administrative interfaces or other connected infrastructure.

Current exploitation status and timeline

The vulnerability was disclosed and patched on 13 January 2026. On 8 September 2026, SOCRadar reported active exploitation and the deployment of PivotC2, confirming that CVE-2025-25249 had moved beyond a theoretical risk.

The available reporting does not name the threat actor, identify particular victim organisations or quantify the number of compromised devices. However, the repeatable exploitation tooling, custom payload and FortiGate-specific credential functions indicate an organised campaign built to obtain continuing access and valuable network secrets.

The recovered PivotC2 version and signs of ongoing development also mean defenders should not assume every deployment will be identical. File names, infrastructure or implementation details could change as the operators refine the tool.

What organisations should do now

Administrators should verify the exact FortiOS or FortiSwitchManager version installed and apply Fortinet’s available updates without delay. Appliances that expose UDP port 5246 should receive priority, particularly where CAPWAP access is available from the public internet.

Where external CAPWAP access is not required, organisations should restrict UDP 5246 to trusted management sources. Teams should also review appliances for evidence of the exploitation chain, including unexpected JavaScript or Node.js execution, temporary payload files, fortirun.bin and unexplained outbound TLS sessions.

If compromise is suspected, simply patching the vulnerability is not sufficient because PivotC2 can extract reusable secrets. Affected organisations should isolate and investigate the appliance, remove unauthorised components, review configuration changes, and rotate VPN pre-shared keys, SSL-VPN credentials, wireless passwords and administrator credentials that may have been exposed.

Originally reported by cybersecuritynews.com.

Share this bulletin

About the Author

Rob McBride Headshot - CyPro Partner and leading cyber security expert

Rob McBride

Partner

  • CISSP
  • ACA Chartered Accountant
  • MPhil
  • BSc
  • SOC 2
  • ISO 27001

Rob McBride

Rob is a Founding Partner at CyPro and a highly experienced CISO. Beginning his career with a successful tenure at Deloitte, Rob has since amassed a wealth of experience, notably serving as a cyber security advisor to the UK government and spearheading cloud security transformations for several global banks.

At CyPro, Rob leads the managed service business line, working extensively across multiple sectors including telecommunications, technology, higher education, travel, and retail. He is passionate about equipping small and medium-sized businesses (SMBs) with robust cyber security strategies to fuel their growth.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call