Attackers use Fortinet RCE to deploy PivotC2 RAT
Attackers exploited unauthenticated Fortinet RCE (CVE-2025-25249) to deploy a Node.js RAT called PivotC2, scanning 30,000+ IPs and infecting 178 devices, mainly in the U.S.
Attackers exploited an unauthenticated remote code execution vulnerability in Fortinet products tracked as CVE-2025-25249 to install a Node.js remote access trojan named PivotC2. The campaign scanned more than 30,000 IP addresses and confirmed 178 infected devices, primarily in the United States. At least two of those intrusions involved data exfiltration.
Fortinet patched the issue in January for FortiOS and FortiSwitchManager. The company’s advisory warned the flaw “may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.” The U.S. Cybersecurity and Infrastructure Security Agency added CVE-2025-25249 to its Known Exploited Vulnerabilities catalog and directed federal agencies to apply patches within three days under BOD 26-04.
Security firm SOCRadar reported the exploit has been used to deploy PivotC2, a FortiGate post-exploitation backdoor written in Node.js. The tool provides attackers with an interactive shell, traffic tunneling, network scanning and the ability to harvest device configurations. SOCRadar observed use of the tool since at least July 2026 and attributed the activity to a Russian-speaking cybercrime actor. The firm also noted the malware was likely developed using AI techniques.
CVE-2025-25249 is a heap-based buffer overflow. Such flaws can let attackers overwrite memory and gain control of program execution. Because the vulnerability is exploitable without authentication, exposed devices could be reached without valid credentials.
Fortinet released fixes in FortiOS versions 7.6.4, 7.4.9, 7.2.12 and 7.0.18, and in FortiSwitchManager versions 7.2.7 and 7.0.6. Organizations operating affected software are advised to update to these or later releases, verify device integrity and review logs for signs of compromise. Incident response teams are advised to isolate impacted devices, check for unexpected outbound connections or new processes, inspect configuration changes and consider restoring from known-good backups.
Vendors and responders continue to investigate the scope of the campaign. Operators of Fortinet products are urged to confirm they are running the patched versions or newer builds.








