fortinet-fortios-pivotc2

FortiGate firewalls at the network edge are being compromised by attackers through a vulnerability in FortiOS that does not require a password. The vulnerability is being actively exploited, and the fix is an update.

Researchers at SOCRadar have observed a campaign exploiting CVE-2025-25249, a vulnerability in FortiOS and FortiSwitchManager. It allows an unauthenticated attacker to execute code on the device via specially crafted requests. On compromised devices, attackers install PivotC2—a remote access program that provides full control: an interactive console, traffic redirection, network scanning, and configuration extraction.

The scale of the attack is significant: over 30,000 addresses were targeted, and the U.S. agency CISA has added the vulnerability to its list of actively exploited vulnerabilities, setting a deadline for federal agencies to address it. The attacks are attributed to a financially motivated, Russian-speaking criminal group.

Why this matters for a small business: The firewall at the network entrance is often a FortiGate running FortiOS, installed and managed by the IT provider. Whoever controls the firewall can see and redirect all of the company’s traffic—email, access to online banking, and business applications. This isn’t a vulnerability that antivirus software can block; it can only be fixed by updating the system on the device.

The good news is that you don't have to be the expert. All you need to do is ask your network administrator a few questions: Do you have a FortiGate or a FortiSwitchManager at the entry point? Has it been updated to a patched version—FortiOS 7.6.4, 7.4.9, 7.2.12, 7.0.18, or FortiSwitchManager 7.2.7, 7.0.6? Is the device’s management interface blocked from the internet?

Fortinet has released the patched versions, so the next step depends on who is managing the equipment. An unpatched firewall is an open door that the company doesn't see, but that attackers are actively looking for.

Sources:

  • SecurityWeek | https://www.securityweek.com/fortinet-code-execution-flaw-exploited-in-pivotc2-rat-attacks/
  • The Hacker News | https://thehackernews.com/2026/09/cisa-flags-exploited-cisco-citrix.html

This article was generated with AI assistance.

Request a quote

← All news