Hackers Are Exploiting a Fortinet Flaw to Plant Remote-Control Malware on Network Devices

A security bug in Fortinet's firewall and switch software is being used to silently take over devices and steal data. More than 178 machines are already infected, and the US government is telling federal agencies they have three days to patch.

ThreatVectr Newsdesk· 3 min read
Photoreal news-editorial shot of a dimly lit server rack in a data center, amber status LEDs glowing on a network security appliance, subtle warning light refle
Share

Key points

  • CVE-2025-25249, a high-severity bug in Fortinet's FortiOS and FortiSwitchManager products, was patched in January 2026 but remains unpatched on thousands of devices.
  • Hackers scanned more than 30,000 IP addresses and successfully infected 178 devices with a remote-control tool called PivotC2.
  • At least two intrusions led to data being stolen, with attacks focused mainly on US organisations.
  • CISA, the US government's cybersecurity agency, added the flaw to its must-patch list on Wednesday and gave federal agencies three days to act.
  • Fixed versions exist across four FortiOS releases and two FortiSwitchManager releases; organisations running older versions should update immediately.

What happened?

Criminals have been breaking into Fortinet network devices by exploiting a flaw that lets anyone on the internet run commands on an affected machine without needing a password. Once inside, they install a piece of malicious software called PivotC2, a remote-access tool (software that gives attackers full keyboard control of a machine from anywhere in the world) built specifically to burrow deep into a network.

The flaw, tracked as CVE-2025-25249, is caused by a heap-based buffer overflow: a programming mistake that lets an attacker send a specially crafted request to the device and hijack it. Fortinet scored it 7.4 out of 10 for severity and published a fix in its own advisory back in January. Many organisations have not yet applied it.

Threat intelligence firm SOCRadar, first to report the active exploitation, says the hackers targeted more than 30,000 IP addresses, successfully infected 178 devices, and in at least two cases walked off with data. The attacks focus mainly on US targets. SOCRadar believes the campaign is run by a Russian-speaking criminal group and that PivotC2 was likely built with AI assistance.

What does PivotC2 actually do?

Once installed, PivotC2 is a full break-in toolkit. It gives the attackers an interactive shell (a text-based control panel, essentially a remote keyboard into the device), lets them tunnel traffic through the infected machine to hide their movements, scan the wider internal network for further targets, and scrape device configuration files that may contain passwords and network maps.

In short: a device infected with PivotC2 becomes a quiet foothold inside an organisation's network, useful for escalating an attack far beyond the original entry point.

What versions are affected, and what should organisations do?

Fortinet shipped fixes across six software releases. If your organisation runs FortiOS or FortiSwitchManager, check your version against this table:

Product Vulnerable Fixed in
FortiOS Below 7.6.4 7.6.4 or newer
FortiOS Below 7.4.9 7.4.9 or newer
FortiOS Below 7.2.12 7.2.12 or newer
FortiOS Below 7.0.18 7.0.18 or newer
FortiSwitchManager Below 7.2.7 7.2.7 or newer
FortiSwitchManager Below 7.0.6 7.0.6 or newer

CISA added CVE-2025-25249 to its Known Exploited Vulnerabilities catalogue on Wednesday, triggering a binding directive that gives US federal agencies three days to patch. Private organisations are not legally bound by that deadline, but the live exploitation makes waiting a poor choice.

If your IT team manages Fortinet equipment, push the update now, then check device logs for unexpected outbound connections or new administrator accounts. If you think a device may already be infected, bring in an incident-response team before wiping and rebuilding: you need to understand whether the attackers moved further into your network first.

© 2026 Threat Vectr