Skip to content
Auto-CTI
Back to today
KEV NEW CRITICAL C1

Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks

C SecurityWeek · · CVE-2025-25249

Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

Key metrics

CVSS
8.1
EPSS
1%
KEV due date
12 September 2026

Affected versions

fortios fortiswitchmanager fortisase 25.1.39

Key insight

The vulnerability is being actively exploited by a Node.js-based RAT (PivotC2) and has been added to the CISA KEV catalog, indicating rapid proliferation and heightened risk.

Description

CVE-2025-25249 is a high-severity, unauthenticated remote code execution vulnerability in Fortinet FortiOS and FortiSwitchManager with a CVSS score of 7.4. Attackers are actively exploiting the flaw to deploy a Node.js-based remote access trojan (PivotC2). CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog and is urging US federal agencies to patch within three days. Patches are available for FortiOS versions 7.6.4, 7.4.9, 7.2.12, and 7.0.18, and FortiSwitchManager versions 7.2.7 and 7.0.6.

Risk score

100
cvss base
81.00
kev bonus
20.00
epss bonus
0.00
poc bonus
15.00
raw before weight
116.00
industry weight
1.21
freshness factor
1.00
exploitability factor
1.00
days old
0.00
vendor mismatch penalty
0.00

Path: operational

ESC