A patch that has existed since January is not the same thing as a fix that has been applied. Roughly 30,000 FortiGate appliances found out the difference this month.
The flaw and how it is being used
CVE-2025-25249 is a heap-based buffer overflow in the cw_acd daemon that FortiOS and FortiSwitchManager use to run CAPWAP, the protocol Fortinet uses to centrally manage wireless access points. The daemon listens on UDP port 5246, and because CAPWAP management is exposed on a large share of internet-facing FortiGate deployments, an unauthenticated attacker who sends a specially crafted request to that port can trigger memory corruption and execute arbitrary code, no credentials required. Fortinet rated it up to 9.8 on the CVSS scale and shipped a fix on January 13, 2026.
Researchers at SOCRadar have tracked active exploitation delivering PivotC2, a custom Node.js remote access tool built specifically to operate on FortiGate appliances once an attacker is inside. The campaign has scanned or targeted an estimated 30,000 IP addresses, with 178 confirmed victim sessions logged so far, and analysts assess with high confidence that exploitation has been running since at least July 2026, two full months before CISA added the CVE to its Known Exploited Vulnerabilities catalog on September 9.
The eight-month gap is the real story
This is not a zero-day. A fix has been publicly available since January. What made the September KEV addition necessary is that a meaningful population of FortiGate appliances, across two months of confirmed active exploitation, still had not applied it. FortiGate is one of the most widely deployed firewall platforms among European small and mid-sized businesses and the managed service providers that support them, precisely because it is affordable and well-regarded, which makes it a large and attractive target once a working exploit and a purpose-built RAT are circulating.
What to check right now
Confirm your FortiOS or FortiSwitchManager version against Fortinet’s January advisory rather than assuming a routine update cycle already covered it. Restrict access to CAPWAP and UDP port 5246 to only the network segments that actually need it, since internet exposure is the precondition every successful attack in this campaign has shared. Then look for the specific signs of compromise SOCRadar has published: unexpected Node.js processes, unfamiliar outbound connections consistent with a command-and-control channel, and any device behaviour that suggests it has been sitting in an attacker’s target list since summer.
If you are not certain every firewall in your estate is current, or you want a proper audit of what is reachable from the internet before an attacker finds it for you, contact Excello Digital. We help European businesses close the gap between a patch existing and a patch actually being applied.
