Threat intelligence disclosures have detailed a major ongoing intrusion campaign actively weaponizing a heap-based buffer overflow flaw in network security operating systems. Threat actors transmit malformed network packets to drop shell scripts, executing Node.js payloads to establish interactive reverse command shells.
The attack campaign targets Fortinet FortiOS, FortiSwitchManager, and FortiSASE product builds via vulnerability CVE-2025-25249. Adversaries send crafted network requests to vulnerable appliances, executing single-line JavaScript commands via Node.js to download and execute a second-stage decrypted payload known as PivotC2. The post-exploitation framework supports interactive shell access, network scanning routines, and local configuration harvesting. Threat telemetry estimates over 3,000 IP addresses have been targeted, resulting in verified infections across 178 enterprise edge devices globally.
Subverting perimeter security operating systems exposes internal enterprise subnets to automated compromise pipelines. Possessing remote code execution authority over security gateways allows adversaries to intercept encrypted transit data, harvest VPN service credentials, and route malicious traffic into corporate subnets.
– Upgrade FortiOS, FortiSwitchManager, and FortiSASE software builds immediately to current vendor maintenance releases.
– Restrict public internet access to appliance management interfaces by enforcing zero-trust pre-authentication controls.
– Inspect system process trees for anomalous shell script executions or unauthorized Node.js daemon spawns.
– Monitor outbound network traffic for unverified C2 beacon connections originating from security gateway IP addresses.
Perimeter gateway protection demands rigid memory boundary checks and rapid patch execution to ensure enterprise security platforms remain insulated from unauthenticated remote code execution. #CodeDefence #Fortinet #FortiOS #PivotC2 #NodeJS #BufferOverflow #RCE #AppSec #NetworkSecurity
/
