Hackers Actively Exploiting FortiGate Firewalls to Deploy Custom Node.js Malware
Brief
An active exploitation campaign targeting FortiGate firewalls, in which attackers weaponize a critical vulnerability to plant a custom-built Node.js remote access trojan (RAT) that turns compromised perimeter devices into long-term footholds for espionage and data theft.
The SOCRadar Threat Research Unit (STRU) has identified, with high confidence, that threat actors are actively exploiting CVE-2025-25249 , a critical heap-based buffer overflow flaw affecting the cw_acd daemon in FortiOS and FortiSwitchManager.
Rated 9.8 on the CVSSv3 scale, the vulnerability allows remote, unauthenticated attackers to execute arbitrary code by sending specially crafted requests to the CAPWAP Control service, which listens on UDP port 5246.
Fortinet uses CAPWAP to manage wireless access points centrally, making the daemon reachable on many internet-facing FortiGate appliances.
