Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks
SOCRadar has reported active exploitation of CVE-2025-25249, an unauthenticated remote code execution vulnerability in Fortinet's FortiOS and FortiSwitchManager products. Attackers are leveraging this heap-based buffer overflow flaw to install the PivotC2 RAT, which grants them persistent access through features like traffic tunneling and network scanning. The incident has impacted 178 devices across over 30,000 targeted IPs, primarily affecting US entities and resulting in data exfiltration in at least two cases. CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog, prompting urgent patch recommendations to versions 7.6.4, 7.4.9, 7.2.12, and 7.0.18 for FortiOS, and 7.2.7 and 7.0.6 for FortiSwitchManager.