Fortinet FortiOS and FortiSwitchManager CAPWAP Daemon Heap-Based Buffer Overflow – Actively Exploited via PivotC2 RAT (CVE-2025-25249)

Release Date: 9th September 2026 (Added 10 September 2026)

Impact : CRITICAL

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations and System/Network administrators that operate a Fortinet FortiGate firewall or FortiSwitchManager. This alert is intended to be understood by technical users and systems administrators, and requires urgent action given confirmed, large-scale active exploitation.

What is it?

CVE-2025-25249 is a critical heap-based buffer overflow in the cw_acd daemon of FortiOS and FortiSwitchManager, which handles CAPWAP (Control and Provisioning of Wireless Access Points) traffic on UDP port 5246. An unauthenticated remote attacker can send specially crafted CAPWAP packets to trigger the overflow and execute arbitrary code on the affected appliance, with no credentials or user interaction required.

Reference

  1. https://www.fortiguard.com/psirt/FG-IR-25-084
  2. https://nvd.nist.gov/vuln/detail/CVE-2025-25249
  3. https://socradar.io/blog/cve-2025-25249-pivotc2-fortigate-rat/