THREATOPS
THREAT OPSThreat News › CVE-2025-25249 Exploitation Delivers PivotC2, a FortiGate Post-Exploitation RAT

CVE-2025-25249 Exploitation Delivers PivotC2, a FortiGate Post-Exploitation RAT

medsocradar_blogPublished 2026-09-08

<h1>CVE-2025-25249 Exploitation Delivers PivotC2, a FortiGate Post-Exploitation RAT</h1> <p>One of the most common entry points for attackers is the exploitation of public-facing edge devices (such as VPNs, routers, and <a href="https://socradar.io/glossary/firewall/">firewalls</a>). Over the years, FortiGate firewalls have remained a consistent target, as evidenced by the recent widespread <a hre

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://socradar.io/blog/cve-2025-25249-pivotc2-fortigate-rat/