Skip to content

CVE-2025-25249: Fortinet FortiOS cw_acd CAPWAP Heap Overflow to Unauthenticated RCE

HTS

HERMES THREAT SCORE & FIREWALL PERIMETER RISK

Target: Fortinet FortiOS cw_acd CAPWAP Daemon (UDP 5246 / Fabric)
Confidence: 99%
98 / 100
CRITICAL

Measures real-world operational relevance, exploit weaponization, and active threat posture.

Dimension Breakdown
Exploitability 20 / 20
Threat Activity 20 / 20
Weaponization 20 / 20
Exposure 19 / 20
Prevalence 20 / 20
Impact 20 / 20
Exploit Maturity 20 / 20
Attack Chain Potential 20 / 20
βš–οΈ Divergence & Operational Rationale

Hermes elevates CVE-2025-25249 to 98 (CRITICAL). Unlike web interface vulnerabilities that can be mitigated behind management ACLs, the vulnerable cw_acd daemon listens on perimeter-exposed UDP port 5246 (CAPWAP / FortiTelemetry fabric). State-aligned threat actors actively exploit this flaw in the wild to drop PivotC2, establishing persistent out-of-band proxy channels into corporate LANs.

πŸ•ΈοΈ Connected Knowledge Graph & Provenance

CVE-2025-25249: Fortinet FortiOS cw_acd CAPWAP Heap Buffer Overflow RCEVULNERABILITY

Connected Nodes: 1
Active Relationships (Outgoing)
→ affectsPRODUCTFortinet FortiOS Gateway
98% VERY_HIGH

Software platform affected by security vulnerabilities and agentic attack patterns.

πŸ” Why is this related? (Evidence & Provenance)

“Confirmed security vulnerability in Fortinet FortiOS Gateway documented in Hermes dossier.”

Supporting Verified Evidence:

MetricTechnical SpecificationOperational Impact
CVE IdentifierCVE-2025-25249Universal vulnerability identifier
Vendor AdvisoryFG-IR-25-084Fortinet PSIRT security advisory
CVSS v3.1 Score9.8 (Critical)CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
FIRST EPSS Score0.76% (53.11th percentile)Rapidly accelerating following KEV listing
CISA KEV StatusAdded on September 9, 2026Mandatory remediation under BOD 26-04
Vulnerable Servicecw_acd daemon (CAPWAP Wireless Controller)UDP port 5246 / FortiTelemetry Fabric
AuthenticationNone (Unauthenticated remote exploit)Zero-touch network attack surface
Observed ImplantPivotC2 (Node.js Post-Exploitation RAT)Interactive shell, tunneling, config theft

The flaw affects all active release trains of FortiOS and related management products:

  • FortiOS 7.6: Versions 7.6.0 through 7.6.3 (Fixed in 7.6.4 and later);
  • FortiOS 7.4: Versions 7.4.0 through 7.4.8 (Fixed in 7.4.9 and later);
  • FortiOS 7.2: Versions 7.2.0 through 7.2.11 (Fixed in 7.2.12 and later);
  • FortiOS 7.0: Versions 7.0.0 through 7.0.17 (Fixed in 7.0.18 and later);
  • FortiOS 6.4: Versions 6.4.0 through 6.4.16 (Fixed in 6.4.17 and later);
  • FortiSwitchManager 7.2: Versions 7.2.0 through 7.2.6 (Fixed in 7.2.7 and later);
  • FortiSwitchManager 7.0: Versions 7.0.0 through 7.0.5 (Fixed in 7.0.6 and later);
  • FortiSASE: Versions 23.4, 24.1, 24.2 (Fixed in 24.3 and later).

The vulnerability is caused by a memory copy boundary violation (CWE-122) inside the CAPWAP protocol parser implemented by the cw_acd daemon.

CVE-2025-25249 cw_acd Heap Overflow Execution Flow:
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ 1. Unauthenticated Remote Threat Actor β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
β”‚ Malformed UDP CAPWAP packet (Port 5246)
β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ 2. cw_acd Network Packet Listener β”‚
β”‚ β€’ Receives CAPWAP control message β”‚
β”‚ β€’ Reads user-controlled TLV payload length field β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
β”‚ Insufficient bounds validation (malloc(0x200))
β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ 3. Heap Buffer Overwrite (CWE-122 / CWE-787) β”‚
β”‚ β€’ memcpy() copies oversized payload beyond heap chunk β”‚
β”‚ β€’ Overwrites adjacent heap metadata & function pointers β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
β”‚ Control flow hijacking (ROP / Shellcode)
β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ 4. Arbitrary Code Execution on FortiGate β”‚
β”‚ β€’ Spawns root shell or drops PivotC2 RAT binary β”‚
β”‚ β€’ Establishes outbound TLS reverse tunnel to C2 β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

The cw_acd binary processes CAPWAP (Control and Provisioning of Wireless Access Points) encapsulation headers. In the packet decoding routine:

  1. The daemon allocates a fixed-size buffer on the heap (typically 512 bytes, 0x200) to store reconstructed message fragments.
  2. When parsing Type-Length-Value (TLV) message elements, the routine extracts a 16-bit length indicator supplied directly by the remote packet.
  3. The parser calculates the copy size without ensuring the length does not exceed the remaining capacity of the heap buffer.
  4. An invocation of memcpy() transfers up to 65,535 bytes from the UDP socket into the 512-byte heap allocation, corrupting consecutive heap chunks, glibc heap management structures (arena), and function pointers.

By carefully grooming the heap layout with repeated UDP requests, threat actors overwrite function pointer tables in memory. When the daemon attempts to dispatch the next packet handler, execution redirects to attacker-controlled shellcode, achieving unauthenticated root execution on FortiOS.


3. Threat Intelligence & Real-World Exploitation (PivotC2)

Section titled β€œ3. Threat Intelligence & Real-World Exploitation (PivotC2)”

Telemetry from cyber threat intelligence researchers indicates that CVE-2025-25249 is weaponized in targeted intrusions to deploy PivotC2:

  1. PivotC2 Deployment: A lightweight, customized Node.js-based Remote Access Trojan deposited directly into temporary ramdisks (/data/ or /tmp/).
  2. Reverse Proxy Tunneling: PivotC2 establishes an encrypted WebSocket/TLS egress channel to adversary infrastructure, bypassing inbound perimeter firewalls.
  3. Configuration Harvesting: The malware extracts FortiGate firewall configuration archives, including VPN pre-shared keys, administrative password hashes, and routing tables.
  4. Internal Network Pivoting: Threat actors utilize the firewall’s trusted interface connections to scan and compromise internal Active Directory domain controllers.

This pattern is consistent with other edge gateway attacks such as Cisco Secure FMC CVE-2026-20079 and Ivanti EPMM CVE-2026-1281.


Incident responders triaging Fortinet appliances must inspect crash logs and process tables for exploitation artifacts.

Terminal window
# 1. Read FortiOS crash logs for cw_acd segmentation faults
diagnose debug crashlog read | grep -A 5 -B 2 "cw_acd"
# 2. Check running processes for unexpected daemons or Node.js instances
diagnose sys process pidof cw_acd
fnsysctl ps -ef | grep -iE "(node|pivot|sh|bash|python)"
# 3. Check open network sockets on UDP 5246
diagnose netlink socket-list | grep 5246
# 4. Review administrative logins and configuration changes
execute log filter category 1
execute log display

Crash Artifacts

  • Repeated crash records in crashlog indicating Signal 11 (Segmentation fault) in process cw_acd.
  • Unexpected core dump files located in system flash or ramdisk.

Persistence & Malicious Artifacts

  • Anomalous executable files located in /tmp/, /data/, or /var/.
  • Unrecognized cron jobs or startup scripts configured under config system auto-script.
  • Persistent outbound connections from the firewall to unknown external IP addresses on TCP 443/8443.

suricata_cve_2025_25249.rules
alert udp $EXTERNAL_NET any -> $HOME_NET 5246 ( \
msg:"HERMES CODEX - Fortinet FortiOS cw_acd CAPWAP Heap Buffer Overflow (CVE-2025-25249)"; \
flow:to_server; \
byte_test:1,>,0x00,0; \
content:"|00 00|"; offset:2; depth:2; \
byte_test:2,>,1024,4; \
classtype:attempted-admin; \
sid:202525249; rev:1; \
)

  1. Apply Official Firmware Upgrades:
    Download and apply official FortiOS firmware updates:

    • FortiOS 7.6: Upgrade to 7.6.4 or later;
    • FortiOS 7.4: Upgrade to 7.4.9 or later;
    • FortiOS 7.2: Upgrade to 7.2.12 or later;
    • FortiOS 7.0: Upgrade to 7.0.18 or later;
    • FortiOS 6.4: Upgrade to 6.4.17 or later;
    • FortiSwitchManager: Upgrade to 7.2.7 / 7.0.6 or later.
  2. Temporary Workaround (Disable Fabric / Telemetry Access):
    If immediate upgrading is impossible, restrict interface access by disabling fabric / fortitelemetry access on all WAN interfaces:

    Terminal window
    config system interface
    edit "wan1"
    unset allowaccess fabric
    unset allowaccess capwap
    next
    end
  3. Audit for PivotC2 & Rogue Implants:
    Execute diagnose debug crashlog read to verify whether cw_acd crashed prior to patching. Check /data/ and /tmp/ for foreign scripts.

  4. Credential & Secret Rotation:
    Rotate local administrative passwords, FortiGate-to-FortiManager API keys, and IPsec VPN shared secrets if compromise is suspected.