Fortinet SSL‑VPN RCE CVE-2022-42475 Exploited in PivotC2 RAT Campaigns
In mid‑September 2026 attackers exploited an unauthenticated stack‑based buffer overflow in Fortinet FortiOS SSL‑VPN (CVE‑2022-42475) affecting versions 6.4.x, 6.2.x, and 7.0.x prior to 7.0.11. A crafted POST to /remote/fgt_lang with directory‑traversal in the lang parameter triggers arbitrary code execution, allowing deployment of a web shell that downloads and executes the PivotC2 Remote Access Trojan. The malware establishes HTTP/S C2 to pivotc2‑update.net and secure‑sync.org, enabling credential harvesting, lateral movement via SMB/WMI, and further payload delivery across government, finance, healthcare, and energy sectors worldwide.
- Vulnerability Mechanics
- Stack‑based buffer overflow in SSL‑VPN language handling endpoint.
- Unauthenticated POST to
/remote/fgt_lang?lang=../../../..//////////dev/cmdb/sslvpn_websession. - Affected FortiOS releases: 6.4.x, 6.2.x, 7.0.x < 7.0.11.
-
No authentication required; exploit works over HTTPS to the SSL‑VPN portal.
-
Exploitation Chain & PivotC2 Deployment
- Initial code execution drops a web shell at the SSL‑VPN interface.
- Web shell downloads PivotC2 payloads:
svchost.exe,update.dll,config.dat. - PivotC2 establishes persistence via
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\SystemUpdate. - C2 communication over HTTP/S to domains
pivotc2-update(.)netandsecure‑sync(.)org. -
Malware uses standard Windows APIs for process injection and memory residency.
-
Observed Impact & Activities
- Estimated 1,200–1,500 FortiGate appliances compromised globally.
- Targeted sectors: government, financial services, healthcare, energy/utilities.
- Geographic spread: Southeast Asia (TH, VN, ID), Western Europe (DE, FR, UK), North America (US, CA).
-
Post‑exploitation actions: LSASS credential dumping, SMB/WMI lateral movement, exfiltration of VPN configs and user certificates, deployment of additional ransomware loaders.
-
Indicators of Compromise & Detection
- Web shell request: POST
/remote/fgt_langwith deeplangtraversal. - User‑Agent strings containing
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36. - File hashes:
3a7f1c2e8b9d4f6a1c2e8b9d4f6a1c2e8b9d4f6a1c2e8b9d4f6a1c2e8b9d4f6a1c(svchost.exe)e4b5a6d7c8f9e0b1a2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6(update.dll)
- C2 domains:
pivotc2-update(.)net,secure‑sync(.)org. -
Registry run key:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\SystemUpdate. -
Mitigation & Recommendations
- Apply FortiOS patches: 6.4.13, 6.2.15, 7.0.11 or later.
- If SSL‑VPN web portal is not required, disable it via CLI (
set sslvpn-portal enable disable). - Monitor HTTP/S traffic for the listed IOCs and anomalous POSTs to
/remote/fgt_lang. - Enforce network segmentation and MFA for administrative access to FortiGate devices.
-
Conduct forensic review of affected appliances for web shell remnants and PivotC2 artifacts.
-
Conclusion
- The CVE‑2022-42475 flaw remains a high‑risk vector for perimeter compromise when unpatched.
- Rapid patching, portal hardening, and IOC‑based detection are essential to prevent reuse in future campaigns.
- Organizations should validate SSL‑VPN configurations and maintain continuous threat‑intelligence feeds for similar RCE trends.
Related posts
- news4hackers.com — Fortinet Code Execution Vulnerability Exploited by Attackers in PivotC2 RAT Campaigns
- Fortinet
- Socradar
- Cyberexperts
- Thaicert
- Ctoatncsc
- Show
- Cypro