Skip to content
Hackers Exploit FortiGate Vulnerability to Deploy Custom Node.js Remote

Hackers Exploit FortiGate Vulnerability to Deploy Custom Node.js Remote

Linkedin September 9, 2026

Threat actors are exploiting a previously disclosed Fortinet vulnerability to compromise FortiGate appliances and deploy a newly identified post-exploitation framework known as PivotC2, according to an investigation by SOCRadar’s Threat Research Unit .

The campaign represents a significant escalation in the risk associated with CVE-2025-25249 , a heap-based buffer-overflow vulnerability affecting FortiOS, FortiSwitchManager and certain FortiSASE releases. Successful exploitation can allow an unauthenticated remote attacker to execute arbitrary code or commands by sending specially crafted network packets to a vulnerable device.

Although Fortinet disclosed and patched the vulnerability in January 2026, SOCRadar now reports that it has identified evidence of exploitation with “high confidence.” The attackers allegedly used their access to install PivotC2, a custom command-and-control framework designed to operate directly on compromised FortiGate systems.

The development is particularly concerning because firewalls occupy a privileged position at the boundary of corporate networks. Once compromised, they can provide attackers with a platform for monitoring traffic, collecting credentials, establishing persistence and moving into internal environments—often without triggering the endpoint security products deployed on workstations and servers.

The findings also demonstrate how quickly a vulnerability can evolve from a patch-management concern into a post-exploitation problem. Updating vulnerable systems remains essential, but organizations that operated affected releases must now consider whether their devices may already have been compromised before remediation was completed.

PivotC2 Turns the Firewall Into an Attack Platform

SOCRadar described PivotC2 as a post-exploitation command-and-control framework developed using Node.js. Rather than functioning solely as a conventional remote-access Trojan installed on an employee’s computer, the malware is intended to run on or interact with a compromised FortiGate appliance.

This distinction matters. Network appliances are attractive targets because they are continuously online, routinely communicate with the internet and often have extensive visibility into traffic moving between external networks, internal systems and remote users.

A foothold on a firewall may allow an attacker to use the device as a covert relay point, conceal malicious communications among legitimate network traffic or launch follow-on operations against systems protected by the appliance. It could also enable the attacker to maintain access even after compromised endpoints elsewhere in the network have been rebuilt.

SOCRadar’s choice of the name PivotC2 reflects the framework’s apparent role as a pivoting and command-and-control platform. In practical terms, a compromised FortiGate device could become a bridge between an attacker’s external infrastructure and otherwise inaccessible internal assets.

The use of Node.js is also notable. JavaScript-based runtimes provide developers—and malware operators—with built-in networking capabilities, asynchronous communications and cross-platform components. Those features can make it easier to build modular command-and-control tools while complicating analysis for defenders who expect malware on network appliances to appear as conventional native binaries.

However, SOCRadar’s attribution of the observed activity to exploitation of CVE-2025-25249 should be treated as a research assessment rather than an independent confirmation from Fortinet or a government cybersecurity agency. As of publication, the public Fortinet advisory did not appear to contain a corresponding statement confirming active exploitation or identifying PivotC2 by name.

The Vulnerability Behind the Campaign

CVE-2025-25249 is a heap-based buffer overflow in the cw_acd daemon, a Fortinet component associated with the Control and Provisioning of Wireless Access Points protocol, commonly known as CAPWAP.

A heap overflow occurs when software writes more data into an allocated region of memory than it was designed to hold. Under the right conditions, that memory corruption can alter program behavior and potentially allow attacker-controlled code to execute.

In this case, an attacker can reportedly trigger the vulnerability remotely using specially crafted packets. No authentication or user interaction is required, substantially increasing the potential risk to appliances that expose the affected service to untrusted networks.

The attack is not necessarily straightforward, however. The vulnerability’s scoring reflects high attack complexity, meaning successful exploitation may depend on particular conditions or careful manipulation of the vulnerable process. High complexity should not be interpreted as an effective defense: once attackers develop reliable tooling for a vulnerability, they can automate much of the exploitation process.

The NIST National Vulnerability Database lists the issue with a CVSS 3.1 score of 8.1, while Fortinet-associated reporting has cited a vendor score of 7.3. Differences can arise when organizations make different assumptions exploit conditions or downstream impact. Both ratings place the flaw in the high-severity category.

Successful exploitation can affect confidentiality, integrity and availability. An attacker may be able to steal sensitive information, change configurations, install additional software or disrupt the availability of the appliance and the services it protects.

Fortinet’s Product Security team discovered the vulnerability internally and published advisory FG-IR-25-084 on January 13, 2026. At the time, public reporting said no exploitation or proof-of-concept code was known. The reported PivotC2 activity changes the operational context by suggesting that threat actors have moved beyond theoretical exploitation and incorporated the vulnerability into real-world intrusion activity.

Affected Fortinet Products and Fixed Releases

The vulnerability spans multiple FortiOS branches, including versions still widely used in enterprise environments. According to Fortinet’s advisory and corroborating security bulletins, the affected and corrected releases include:

Certain FortiSASE releases were also listed as affected. Administrators should consult the latest Fortinet advisory rather than relying solely on the original version matrix, as vendors may revise affected-release information while an investigation continues.

An Arctic Wolf security bulletin independently documented the vulnerable FortiOS and FortiSwitchManager branches and advised customers to deploy the corrected releases as quickly as possible.

The flaw may also have implications beyond appliances carrying the Fortinet brand. Siemens published a related advisory covering RUGGEDCOM products that incorporate Fortinet technology, illustrating how security defects in embedded third-party components can extend into industrial and operational-technology environments.

Why Compromised Firewalls Present an Exceptional Risk

A firewall is not simply another server. It is a trusted enforcement point that controls connections between security zones. It may terminate virtual private network sessions, inspect encrypted traffic, enforce access policies, route packets and integrate with identity or directory services.

That combination of trust, access and visibility makes edge appliances valuable targets for espionage groups, ransomware operators and initial-access brokers.

An attacker controlling a FortiGate device could potentially use it to observe network activity, identify internal addressing, collect configuration data or discover systems that are not directly reachable from the internet. The device could also become a staging point for credential attacks, lateral movement or data exfiltration.

Because the malicious activity occurs on a network appliance, organizations may have less telemetry than they would for an infected workstation. Traditional endpoint detection and response agents are usually not installed on proprietary firewall operating systems. Security teams must therefore depend on appliance logs, configuration monitoring, network-flow analysis and external threat intelligence.

Attackers also understand that perimeter devices are often patched more cautiously than ordinary endpoints. Updating a firewall may require a maintenance window, redundancy testing, failover planning and verification that routing, VPN and security policies continue to operate correctly. Those operational constraints can leave known vulnerabilities exposed long after fixes become available.

The issue is compounded when an appliance is internet-facing or exposes administrative and fabric-management services more broadly than necessary.

Patching Alone May Not Remove an Existing Intruder

Organizations should upgrade affected systems immediately, but the emergence of a post-exploitation framework means patching should be treated as only one part of the response.

A security update prevents future exploitation of the corrected flaw. It does not necessarily remove malware, unauthorized accounts, implanted configuration changes or stolen credentials left behind by an attacker who compromised the device earlier.

Security teams should therefore investigate vulnerable or recently upgraded FortiGate appliances for evidence of prior access. The investigation should include configuration history, administrator logins, newly created accounts, altered authentication settings, unexpected scripts or files, unusual processes and outbound connections to unfamiliar infrastructure.

Administrators should also review changes to firewall rules, local-in policies, VPN configuration, routing, DNS settings and logging behavior. Attackers who compromise an edge appliance may change settings to preserve access, weaken monitoring or create covert pathways into the internal network.

Where compromise is suspected, organizations should consider rebuilding the appliance from a trusted firmware image and restoring only a verified configuration. Administrative passwords, API keys, VPN credentials and other secrets stored on or used by the device should be rotated. Credentials should be changed from a known-clean system, not from the potentially compromised appliance.

Logs should be exported and preserved before destructive remediation begins. Even if the local records appear incomplete, adjacent systems—including authentication platforms, SIEM deployments, DNS resolvers, routers and network-monitoring tools—may contain evidence of the attacker’s activity.

The investigation should extend beyond the firewall itself. Defenders should look for lateral movement, unusual internal connections, credential use from unexpected locations, new persistence mechanisms on servers and data transfers that began after the suspected initial compromise.

Fortinet’s Temporary Mitigations

For organizations unable to upgrade immediately, Fortinet recommended removing fabric access from affected interfaces or blocking access to the CAPWAP daemon.

The guidance includes restricting CAPWAP control traffic on UDP ports 5246 through 5249 with a local-in policy and limiting access to explicitly trusted device addresses. These controls can reduce exposure to the vulnerable service while an upgrade is prepared.

Temporary mitigations should not be considered permanent substitutes for a security update. Configuration workarounds can be applied incorrectly, undone during later changes or fail to cover an unexpected exposure path. They also do not address a device that was compromised before the mitigation was implemented.

Organizations using Fortinet Security Fabric or wireless-management functionality should carefully test configuration changes to avoid disrupting legitimate management traffic.

Edge Devices Remain a Favored Initial-Access Target

The reported PivotC2 campaign fits a broader trend in which attackers prioritize firewalls, VPN gateways, routers and other perimeter technologies.

These products frequently sit outside conventional endpoint-monitoring coverage and may provide direct access to sensitive networks. They are also discoverable through internet scanning, enabling attackers to identify vulnerable systems at scale once a reliable exploit becomes available.

Edge-device compromises can be particularly difficult to detect when attackers use legitimate administrative functions or modify the underlying appliance rather than deploying familiar malware on endpoints. In some incidents involving other Fortinet vulnerabilities, defenders have faced persistent access, configuration manipulation and activity designed to survive routine remediation.

The presence of a specialized framework such as PivotC2 suggests that at least one threat actor may be investing in tooling tailored to network infrastructure rather than treating the firewall merely as an entry point. That could enable longer-term control of compromised appliances and more efficient pivoting into victim environments.

SOCRadar had not publicly attributed the reported activity to a named state- group or cybercrime operation at the time of its report. Without corroborating infrastructure, victimology or operational evidence, assigning the campaign to a particular actor would be premature.

What Organizations Should Do Now

Security teams should first identify every FortiOS, FortiSwitchManager and FortiSASE deployment in their environment, including backup appliances, disaster-recovery systems, laboratory equipment and devices administered by third-party service providers.

Each appliance should be checked against Fortinet’s current advisory and moved to a fixed release. Externally exposed services should be reviewed and restricted to trusted management networks wherever operationally possible.

Organizations that previously ran vulnerable versions should conduct a retrospective review even if the systems have since been updated. The review window should begin before the January 2026 public disclosure because attackers may have discovered or exploited the vulnerability independently before the advisory was issued.

Defenders should pay particular attention to unusual outbound communications originating from the firewall itself. A device that normally communicates only with management, update, authentication and logging infrastructure should not suddenly initiate connections to unknown internet hosts.

Centralized, tamper-resistant logging is critical. If an attacker gains administrative or operating-system-level control of a firewall, local logs may be modified or deleted. Sending telemetry to an external SIEM or log collector can preserve evidence beyond the attacker’s immediate reach.

Network segmentation can also limit the consequences of a perimeter compromise. A firewall should not provide unrestricted management access to identity systems, virtualization infrastructure, backup platforms or other high-value assets merely because it occupies a trusted network position.

A Shift From Vulnerability Management to Incident Response

CVE-2025-25249 was originally disclosed as a high-severity memory-corruption vulnerability with potentially serious consequences. The reported deployment of PivotC2 changes how exposed organizations should assess that risk.

For defenders, the question is no longer limited to whether a vulnerable FortiGate appliance should be patched. They must also determine whether it was reachable, whether suspicious traffic targeted the affected service and whether an attacker may already have established persistence.

The campaign highlights the strategic value of edge devices and the danger of treating network appliances as passive infrastructure. Modern firewalls are powerful computing platforms with extensive access to organizational traffic and security controls. When compromised, they can become equally powerful tools for attackers.

Organizations should deploy the corrected Fortinet releases, reduce unnecessary exposure and examine previously vulnerable appliances for signs of post-exploitation activity. Where evidence suggests PivotC2 or another implant may be present, the response should escalate from routine patching to a full incident investigation.

Cyber Security Hub

To view or add a , sign in

More articles by The Cyber Security Hub™