FortiOS Security Fabric (CAPWAP)

CVE-2025-25249: FortiGate heap overflow over CAPWAP, exploited months after a quiet fix

A heap overflow in FortiOS's CAPWAP daemon (cw_acd) gives unauthenticated code execution on interfaces with Fabric access enabled. Fixed in 2025, disclosed in January 2026, exploited from July 2026 with 178 confirmed infections.

Published Updated

ExploitedYes, in CISA KEVAdded 9 Sept 2026
Ransomware useNot reportedPer CISA
SeverityHIGHCVSS 3.1 7.4
EPSS3.8%Chance of exploitation in 30 days
Public exploitNot known
FixAvailable

Affected and fixed versions

Product / branchFixed in
FortiOS 7.6.0 to 7.6.37.6.4 or later
FortiOS 7.4.0 to 7.4.87.4.9 or later
FortiOS 7.2.0 to 7.2.117.2.12 or later
FortiOS 7.0.0 to 7.0.177.0.18 or later
FortiOS 6.4 (all versions)No fix. Migrate to a fixed release
FortiSwitchManager 7.2.0 to 7.2.67.2.7 or later
FortiSwitchManager 7.0.0 to 7.0.57.0.6 or later

Always confirm against the vendor advisory, which lists every fixed hotfix.

What it is

FortiGates use CAPWAP to manage FortiAPs and FortiSwitches. The cw_acd daemon handles that traffic on UDP 5246 to 5249 on every interface where the Fabric access service is enabled. A heap overflow in that daemon lets an unauthenticated attacker run code on the firewall.

Fortinet rated it high (CVSS 7.4), partly because ASLR and PIE make exploitation harder. NVD scored it 9.8. Attackers solved the hardening: per SOCRadar, the exploit first leaks memory addresses with a CAPWAP Discovery Request, grooms the heap with Add Station messages, then triggers the overflow and starts a Node.js reverse shell.

The timeline is the real lesson. Fixed releases shipped from August 2025, the advisory came in January 2026, and exploitation started around July 2026. Firewalls kept on older builds for a year were the targets.

Am I affected?

You’re exposed if both are true:

  1. FortiOS is older than 7.6.4, 7.4.9, 7.2.12 or 7.0.18, or on 6.4, which gets no fix. FortiSwitchManager older than 7.2.7 or 7.0.6 is affected too.
  2. The fabric access service is enabled on an interface attackers can reach. Check each interface’s administrative access, or from the CLI:
show system interface | grep -f fabric

Fabric access on the WAN interface is an easy mistake to make, for example when managing remote FortiAPs or FortiSwitches over the internet, and that’s what puts CAPWAP on the internet.

What to do

1. Upgrade to 7.6.4, 7.4.9, 7.2.12, 7.0.18 or later. Use Fortinet’s upgrade path tool, since jumping several releases may need intermediate steps. Firewalls on 6.4 have to move to a supported branch.

2. Remove fabric from interfaces that don’t need it, WAN interfaces above all:

config system interface
    edit "port1"
        set allowaccess ssh https
    next
end

set allowaccess replaces the whole list, so include every service the interface still needs.

3. Where Fabric access is really needed on an exposed interface, use local-in policies to allow UDP 5246-5249 only from your FortiAPs and FortiSwitches. Fortinet’s advisory has a complete example.

4. Treat old, exposed firewalls as possibly compromised. If a FortiGate had Fabric access exposed and was unpatched any time from July 2026, check it (below). If you find signs of compromise:

  • Isolate it and rebuild it on fixed firmware. Upgrading doesn’t remove a running implant.
  • Rotate everything it stored: admin passwords, SSL-VPN and local user passwords, LDAP and RADIUS bind credentials, IPsec and Wi-Fi pre-shared keys.
  • Hunt for lateral movement from the firewall into your network. In two reported cases attackers moved on and stole data.

Detection

  • Sessions to the attacker addresses:
diagnose sys session filter daddr 46.151.29.58
diagnose sys session list
  • The dropped implant: fnsysctl ls -la /tmp/ and look for .i.js.
  • Inbound UDP 5246-5249 from the internet in traffic or local-in logs.
  • Signs of a pivot: RDP, SSH or SMB connections from the firewall’s own address to internal hosts, reverse SSH tunnels, and unusual outbound transfers.

Indicators of compromise

FortiOS ships with Node.js, so a node process alone proves nothing. Look for it together with connections to these addresses.

The .txt list has one IP per line and a fixed address, so a firewall can pull it as an External Dynamic List: https://patchtonight.com/iocs/CVE-2025-25249.txt

IndicatorTypeReported by
46.151.29[.]58IPOutbound connection from compromised FortiGatesSOCRadar via Triskele Labs
146.103.99[.]177IPOutbound connection from compromised FortiGatesSOCRadar via Triskele Labs
/tmp/.i.jsFile pathNode.js implant (PivotC2) dropped on the FortiGateSOCRadar via Triskele Labs

Sources

Page changelog

  • Full analysis published.

KEV status, EPSS score and vendor data refreshed automatically, last on 10 Oct 2026.

Get alerts

A notification when we publish a new analysis or a covered vendor gets a new actively exploited CVE. No account, no email.