NVD disclosure day

Published threat advisories for December 4, 2025

CVE advisoryCRITICAL

CVE-2025-29269

ALLNET ALL-RUT22GW Command Injection Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An OS command injection vulnerability exists in a specific industrial cellular router firmware, potentially allowing unauthenticated attackers to execute arbitrary commands remotely and compromise device operations. This could enable unauthorized control of network edge devices if reachable.

CVE advisoryCRITICAL

CVE-2025-40258

Linux Kernel MPTCP Race Condition Use-After-Free.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A race condition in the Linux kernel's MultiPath TCP (MPTCP) implementation could lead to a use-after-free error, impacting system stability. The vulnerability arises from internal task scheduling and memory management. While resolved, its relevance to your environment requires confirmation.

CVE advisoryCRITICAL

CVE-2025-40252

Linux Kernel qede Driver Out-of-Bounds Read Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in the Linux kernel's QLogic network driver allows an out-of-bounds read when processing malformed network packets. This could impact system stability and potentially expose memory if the affected driver is in use and reachable. Confirmation of the driver's presence and relevance in the environment is a