FortiOS Security Fabric (CAPWAP)
CVE-2025-25249: FortiGate heap overflow over CAPWAP, exploited months after a quiet fix
A heap overflow in FortiOS's CAPWAP daemon (cw_acd) gives unauthenticated code execution on interfaces with Fabric access enabled. Fixed in 2025, disclosed in January 2026, exploited from July 2026 with 178 confirmed infections.
Published Updated
Affected and fixed versions
| Product / branch | Fixed in |
|---|---|
| FortiOS 7.6.0 to 7.6.3 | 7.6.4 or later |
| FortiOS 7.4.0 to 7.4.8 | 7.4.9 or later |
| FortiOS 7.2.0 to 7.2.11 | 7.2.12 or later |
| FortiOS 7.0.0 to 7.0.17 | 7.0.18 or later |
| FortiOS 6.4 (all versions) | No fix. Migrate to a fixed release |
| FortiSwitchManager 7.2.0 to 7.2.6 | 7.2.7 or later |
| FortiSwitchManager 7.0.0 to 7.0.5 | 7.0.6 or later |
Always confirm against the vendor advisory, which lists every fixed hotfix.
What it is
FortiGates use CAPWAP to manage FortiAPs and FortiSwitches. The cw_acd daemon handles that traffic on UDP 5246 to 5249 on every interface where the Fabric access service is enabled. A heap overflow in that daemon lets an unauthenticated attacker run code on the firewall.
Fortinet rated it high (CVSS 7.4), partly because ASLR and PIE make exploitation harder. NVD scored it 9.8. Attackers solved the hardening: per SOCRadar, the exploit first leaks memory addresses with a CAPWAP Discovery Request, grooms the heap with Add Station messages, then triggers the overflow and starts a Node.js reverse shell.
The timeline is the real lesson. Fixed releases shipped from August 2025, the advisory came in January 2026, and exploitation started around July 2026. Firewalls kept on older builds for a year were the targets.
Am I affected?
You’re exposed if both are true:
- FortiOS is older than 7.6.4, 7.4.9, 7.2.12 or 7.0.18, or on 6.4, which gets no fix. FortiSwitchManager older than 7.2.7 or 7.0.6 is affected too.
- The
fabricaccess service is enabled on an interface attackers can reach. Check each interface’s administrative access, or from the CLI:
show system interface | grep -f fabric
Fabric access on the WAN interface is an easy mistake to make, for example when managing remote FortiAPs or FortiSwitches over the internet, and that’s what puts CAPWAP on the internet.
What to do
1. Upgrade to 7.6.4, 7.4.9, 7.2.12, 7.0.18 or later. Use Fortinet’s upgrade path tool, since jumping several releases may need intermediate steps. Firewalls on 6.4 have to move to a supported branch.
2. Remove fabric from interfaces that don’t need it, WAN interfaces above all:
config system interface
edit "port1"
set allowaccess ssh https
next
end
set allowaccess replaces the whole list, so include every service the interface still needs.
3. Where Fabric access is really needed on an exposed interface, use local-in policies to allow UDP 5246-5249 only from your FortiAPs and FortiSwitches. Fortinet’s advisory has a complete example.
4. Treat old, exposed firewalls as possibly compromised. If a FortiGate had Fabric access exposed and was unpatched any time from July 2026, check it (below). If you find signs of compromise:
- Isolate it and rebuild it on fixed firmware. Upgrading doesn’t remove a running implant.
- Rotate everything it stored: admin passwords, SSL-VPN and local user passwords, LDAP and RADIUS bind credentials, IPsec and Wi-Fi pre-shared keys.
- Hunt for lateral movement from the firewall into your network. In two reported cases attackers moved on and stole data.
Detection
- Sessions to the attacker addresses:
diagnose sys session filter daddr 46.151.29.58
diagnose sys session list
- The dropped implant:
fnsysctl ls -la /tmp/and look for.i.js. - Inbound UDP 5246-5249 from the internet in traffic or local-in logs.
- Signs of a pivot: RDP, SSH or SMB connections from the firewall’s own address to internal hosts, reverse SSH tunnels, and unusual outbound transfers.
Indicators of compromise
FortiOS ships with Node.js, so a node process alone proves nothing. Look for it together with connections to these addresses.
The .txt list has one IP per line and a fixed address, so a firewall can pull it as an External Dynamic List: https://patchtonight.com/iocs/CVE-2025-25249.txt
| Indicator | Type | Reported by |
|---|---|---|
| 46.151.29[.]58 | IPOutbound connection from compromised FortiGates | SOCRadar via Triskele Labs |
| 146.103.99[.]177 | IPOutbound connection from compromised FortiGates | SOCRadar via Triskele Labs |
| /tmp/.i.js | File pathNode.js implant (PivotC2) dropped on the FortiGate | SOCRadar via Triskele Labs |
Sources
Page changelog
- Full analysis published.
KEV status, EPSS score and vendor data refreshed automatically, last on 10 Oct 2026.