A Critical Vulnerability in Fortinet Products is Being Exploited to Deploy a Powerful Backdoor
Threat actors have been exploiting an unauthenticated remote code execution (RCE) vulnerability in Fortinet products to deploy a powerful backdoor, known as PivotC2 RAT. This high-severity bug was patched by Fortinet in January, but it appears that some organizations are still vulnerable.
The CVE-2025-25249 flaw is a heap-based buffer overflow issue that allows an attacker to execute arbitrary code or commands via specifically crafted requests. According to SOCRadar, the cybersecurity firm that discovered the exploitation, hackers have been targeting over 30,000 IP addresses, leading to the infection of at least 178 devices with PivotC2.
The attacks are believed to be mounted by a Russian-speaking cybercrime actor and primarily targeted US entities. Two intrusions have resulted in data exfiltration, highlighting the severity of the threat. SOCRadar also believes that the attackers used AI to develop the PivotC2 backdoor, which provides them with interactive shell access, traffic tunneling, network scanning, and configuration harvesting capabilities.
The fact that this vulnerability was patched months ago raises questions about why some organizations are still vulnerable. Fortinet’s patches were rolled out in FortiOS versions 7.6.4, 7.4.9, 7.2.12, and 7.0.18, as well as in FortiSwitchManager versions 7.2.7 and 7.0.6. All organizations using these products are advised to update to the latest versions or newer ones.
The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2025-25249 to its Known Exploited Vulnerabilities catalog, urging federal agencies to patch the vulnerability within three days. This is in line with BOD 26-04’s requirements, which mandate timely patching of known exploited vulnerabilities.
The exploitation of this critical vulnerability highlights the importance of keeping software up-to-date and patching vulnerabilities in a timely manner. Organizations that have not yet patched their systems should do so immediately to prevent the deployment of PivotC2 RAT on their devices.
In conclusion, while the threat is severe, it’s essential for organizations to learn from this incident and take proactive measures to secure their systems. Regularly updating software and staying informed about potential vulnerabilities can help mitigate the risk of exploitation. By taking these steps, organizations can reduce the likelihood of a successful attack and protect themselves against powerful backdoors like PivotC2 RAT.
Source: SecurityWeek — 2026-09-10