NVD disclosure day

Published threat advisories for December 5, 2025

CVE advisoryKnown Exploit

CVE-2025-66644

ArrayOS Command Injection Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Array Networks ArrayOS AG, used in secure access gateways, has a command injection vulnerability. This flaw allows attackers to execute arbitrary commands, potentially leading to unauthorized access and data compromise. Organizations using affected versions face significant business risk due to the potential for system

• CISA KEV

CVE advisoryCRITICAL

CVE-2025-64054

Fanvil X210 Reflected XSS Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A reflected cross-site scripting vulnerability in Fanvil IP phones could allow an attacker to cause a denial of service or execute arbitrary commands via a crafted POST request to the web configuration interface. The relevance of this vulnerability depends on the network reachability of these devices, which are typical