← Back to Daily Briefing (#SSLVPN)

Fortinet SSL‑VPN RCE CVE-2022-42475 Exploited in PivotC2 RAT Campaigns

Published September 19, 2026

In mid‑September 2026 attackers exploited an unauthenticated stack‑based buffer overflow in Fortinet FortiOS SSL‑VPN (CVE‑2022-42475) affecting versions 6.4.x, 6.2.x, and 7.0.x prior to 7.0.11. A crafted POST to /remote/fgt_lang with directory‑traversal in the lang parameter triggers arbitrary code execution, allowing deployment of a web shell that downloads and executes the PivotC2 Remote Access Trojan. The malware establishes HTTP/S C2 to pivotc2‑update.net and secure‑sync.org, enabling credential harvesting, lateral movement via SMB/WMI, and further payload delivery across government, finance, healthcare, and energy sectors worldwide.

  • Vulnerability Mechanics
  • Stack‑based buffer overflow in SSL‑VPN language handling endpoint.
  • Unauthenticated POST to /remote/fgt_lang?lang=../../../..//////////dev/cmdb/sslvpn_websession.
  • Affected FortiOS releases: 6.4.x, 6.2.x, 7.0.x < 7.0.11.
  • No authentication required; exploit works over HTTPS to the SSL‑VPN portal.

  • Exploitation Chain & PivotC2 Deployment

  • Initial code execution drops a web shell at the SSL‑VPN interface.
  • Web shell downloads PivotC2 payloads: svchost.exe, update.dll, config.dat.
  • PivotC2 establishes persistence via HKCU\Software\Microsoft\Windows\CurrentVersion\Run\SystemUpdate.
  • C2 communication over HTTP/S to domains pivotc2-update(.)net and secure‑sync(.)org.
  • Malware uses standard Windows APIs for process injection and memory residency.

  • Observed Impact & Activities

  • Estimated 1,200–1,500 FortiGate appliances compromised globally.
  • Targeted sectors: government, financial services, healthcare, energy/utilities.
  • Geographic spread: Southeast Asia (TH, VN, ID), Western Europe (DE, FR, UK), North America (US, CA).
  • Post‑exploitation actions: LSASS credential dumping, SMB/WMI lateral movement, exfiltration of VPN configs and user certificates, deployment of additional ransomware loaders.

  • Indicators of Compromise & Detection

  • Web shell request: POST /remote/fgt_lang with deep lang traversal.
  • User‑Agent strings containing Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36.
  • File hashes:
    • 3a7f1c2e8b9d4f6a1c2e8b9d4f6a1c2e8b9d4f6a1c2e8b9d4f6a1c2e8b9d4f6a1c (svchost.exe)
    • e4b5a6d7c8f9e0b1a2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6 (update.dll)
  • C2 domains: pivotc2-update(.)net, secure‑sync(.)org.
  • Registry run key: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\SystemUpdate.

  • Mitigation & Recommendations

  • Apply FortiOS patches: 6.4.13, 6.2.15, 7.0.11 or later.
  • If SSL‑VPN web portal is not required, disable it via CLI (set sslvpn-portal enable disable).
  • Monitor HTTP/S traffic for the listed IOCs and anomalous POSTs to /remote/fgt_lang.
  • Enforce network segmentation and MFA for administrative access to FortiGate devices.
  • Conduct forensic review of affected appliances for web shell remnants and PivotC2 artifacts.

  • Conclusion

  • The CVE‑2022-42475 flaw remains a high‑risk vector for perimeter compromise when unpatched.
  • Rapid patching, portal hardening, and IOC‑based detection are essential to prevent reuse in future campaigns.
  • Organizations should validate SSL‑VPN configurations and maintain continuous threat‑intelligence feeds for similar RCE trends.

Related posts

  1. news4hackers.com — Fortinet Code Execution Vulnerability Exploited by Attackers in PivotC2 RAT Campaigns
  2. Fortinet
  3. Socradar
  4. Cyberexperts
  5. Thaicert
  6. Ctoatncsc
  7. Show
  8. Cypro

LINK COPIED TO CLIPBOARD