Skip to finding
§
High
Edge — FortiGate
Confirmed
CVE-2025-25249

PivotC2 operators are taking over FortiGate appliances through CAPWAP.

Network reachability to the CAPWAP control service on UDP/5246 is the prerequisite.

Affects

FortiOS firewall appliances and FortiSwitchManager network-management appliances.

What it enables

Unauthenticated code execution and interactive appliance control

Discover the exposed CAPWAP service and derive firmware-specific image and data addresses from its response.→↓Heap-groom cw_acd with Add Station messages.→↓Send a crafted Image Data message that overwrites allocator pointers.→↓Convert the resulting write into an execvp control-flow pivot.→↓Start a Node.js reverse shell and install the PivotC2 implant for shell, tunneling, scanning and configuration theft.
Why this matters

This leads ahead of the higher-ranked Bluetooth disclosure because operators have already converted the FortiGate flaw into reverse-shell control, while the Bluetooth paths have no public reproduction.

Detail, proof-of-concept code and 3 sources
Required access

Network reachability to the CAPWAP control service on UDP/5246

Affected versions

FortiOS 7.6.0–7.6.3, FortiOS 7.4.0–7.4.8, FortiOS 7.2.0–7.2.11, FortiOS 7.0.0–7.0.17, FortiOS 6.4 releases, FortiSwitchManager 7.2.0–7.2.6, FortiSwitchManager 7.0.0–7.0.5

A crafted Image Data message turns the cw_acd heap overflow into an arbitrary eight-byte write, which the observed exploit converts into an execvp pivot and Node.js reverse shell.

The installed PivotC2 implant supports shell access, tunneling, scanning, and configuration theft.

Evidence
SOCRadar campaign telemetry and reverse engineering of the in-the-wild exploit and PivotC2 implantCISA Known Exploited Vulnerabilities catalog entry added 2026-09-09GitHub Advisory Database affected-version record
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Thursday, September 10, 2026