Attackers are actively exploiting CVE-2025-25249, a critical unauthenticated heap-based buffer overflow in the cw_acd daemon of FortiOS and FortiSwitchManager, against internet-facing FortiGate appliances. The campaign deploys fortirun.bin and a staged Node.js payload that installs PivotC2, a custom remote-access framework supporting encrypted command-and-control, tunneling, file transfer, and port forwarding. PivotC2 steals FortiGate configurations and decrypts stored credentials, including VPN keys and administrative credentials, while also conducting subnet discovery and port scanning.
SOCRadar reported scans of more than 30,000 FortiGate IP addresses and compromise of 178 devices, with the largest infection concentration in the United States. Two confirmed U.S. intrusions involved lateral movement, browser-credential theft, RDP configuration abuse, and Microsoft Exchange mailbox-data exfiltration. The operators are assessed as likely Russian-speaking, financially motivated cybercriminals; organizations should apply Fortinet’s patched releases, limit external CAPWAP exposure, investigate Node.js artifacts and suspicious sessions, and rotate credentials after suspected compromise.

See which actors are running it and whether you're in range.
6 events from the most recent confirmed update back to the earliest known activity.
CISA added Fortinet CVE-2025-25249 to its Known Exploited Vulnerabilities catalog, identifying the cw_acd heap-based buffer-overflow flaw as exploited in the wild. The Canadian Centre for Cyber Security updated advisory AV26-023 following the KEV addition.
Fortinet disclosed CVE-2025-25249, a CVSS 9.8 unauthenticated remote-code-execution flaw in the cw_acd daemon of FortiOS and FortiSwitchManager, and issued patches.
CSIRT Panamá issued an advisory with additional PivotC2-related indicators, including hashes for fortirun.bin, payload.js, and run.ps1; a stager URL; alternate C2 endpoints; and associated Tor obfs4proxy infrastructure. It advised that patching does not remove existing implants and recommended rebuilding confirmed-compromised devices, rotating exposed credentials, and investigating potential internal pivoting.
Technical reporting described CVE-2025-25249 exploitation through CAPWAP Discovery Request, Add Station, and Image Data messages to bypass ASLR, groom the heap, and trigger code execution that deploys a Node.js reverse shell/PivotC2. It also identified outbound connections to 46.151.29[.]58 and 146.103.99[.]177 and the dropped payload path /tmp/.i.js as indicators associated with the activity.
SOCRadar reported that campaign operators scanned more than 30,000 FortiGate IP addresses and compromised 178 devices, with the greatest concentration in the United States. Investigators confirmed two U.S. intrusions involving lateral movement, browser credential theft, RDP configuration abuse, and Exchange mailbox-data exfiltration to Wasabi storage buckets; the activity was assessed as Russian-speaking and financially motivated.
A campaign exploited internet-exposed FortiGate appliances through CVE-2025-25249, using fortirun.bin and automation scripts to deploy a Node.js stager and the PivotC2 remote-access framework. PivotC2 harvests FortiGate configurations and can decrypt stored VPN, SSL-VPN, wireless, and administrator credentials.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 17 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
18 references tracked. Mallory keeps watching after this page renders.
boho.or.kr
Open sourcecsirt.bj
Open sourcecybersecuritynews.com
Open sourcethreataft.com
Open sourcecve.org
Open sourcefortiguard.com
Open sourcefortiguard.com
Open sourcecert-portal.siemens.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.