SECURITY researchers report that a high-severity, unauthenticated remote code execution vulnerability in Fortinet products, tracked as CVE-2025-25249 (CVSS 7.4), has been exploited to deploy the PivotC2 Node[.]js RAT. Described as a heap-based buffer overflow, the flaw was patched in January 2026 across FortiOS and FortiSwitchManager. Fortinet’s advisory states that an attacker could remotely execute arbitrary code or commands via specially crafted requests, without needing authentication.
FortiGate post-exploitation tooling, such as PivotC2, has been observed providing interactive shell access, traffic tunneling, network scanning and configuration harvesting capabilities, according to SOCRadar.
SOCRadar warns that threat actors have been exploiting CVE-2025-25249 to infect vulnerable devices, targeting more than 30,000 IP addresses and compromising 178 devices with PivotC2. The attacks appear to have predominantly hit United States entities, with at least two intrusions resulting in data exfiltration. The research firm attributes the activity to a Russian‑speaking cybercrime actor and notes that PivotC2 may have been developed with AI assistance, with operations dating back to at least July 2026.
In response, U.S. CISA added CVE-2025-25249 to the Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to patch within three days as part of compliance with directive BOD 26-04. Fortinet has released patches for FortiOS versions 7.6.4, 7.4.9, 7.2.12 and 7.0.18, and FortiSwitchManager versions 7.2.7 and 7.0.6; organisations should update to these or newer builds.