Key Facts
SecurityWeek reports that attackers are exploiting CVE-2025-25249, an unauthenticated remote-code-execution vulnerability in Fortinet products, to deploy the PivotC2 Node.js remote-access trojan. The report cites SOCRadar research describing 178 infected devices.
Technical Details
Fortinet’s advisory describes CVE-2025-25249 as a heap-based buffer overflow that may allow a remote unauthenticated attacker to execute arbitrary code or commands through specifically crafted requests. SecurityWeek says the affected products include FortiOS and FortiSwitchManager.
Impact & Mitigation
Update to FortiOS 7.6.4, 7.4.9, 7.2.12, or 7.0.18, or newer releases, and FortiSwitchManager 7.2.7 or 7.0.6, or newer releases, as listed in the report. Investigate suspected compromises for the PivotC2 capabilities described by SOCRadar, including shell access, tunneling, scanning, and configuration harvesting.
