POSTING DATE: 2025/12/17

[VULNERABILITY ALERT] CISA Adds 7 Known Exploited Vulnerabilities to KEV Catalog (2025/12/08-2025/12/14)

  • Subject: [VULNERABILITY ALERT] CISA Adds 7 Known Exploited Vulnerabilities to KEV Catalog (2025/12/08-2025/12/14)


  • Content Description:
    • Forwarded from Taiwan Computer Emergency Response Team/Coordination Center TWCERTCC-200-202512-00000007
    • [CVE-2022-37055] D-Link Routers Buffer Overflow Vulnerability (CVSS v3.1: 9.8)
    • [Exploited by Ransomware: Unknown] D-Link routers contain a Buffer Overflow vulnerability, which has a high impact on confidentiality, integrity, and availability. Affected products may have reached End-of-Life (EoL) and/or End-of-Service (EoS) status, and users should stop using these products.
    • [CVE-2025-66644] Array Networks ArrayOS AG OS Command Injection Vulnerability (CVSS v3.1: 7.2)
    • [Exploited by Ransomware: Unknown] Array Networks ArrayOS AG contains an OS Command Injection vulnerability that may allow attackers to execute arbitrary commands.
    • [CVE-2025-6218] RARLAB WinRAR Path Traversal Vulnerability (CVSS v3.1: 7.8)
    • [Exploited by Ransomware: Unknown] RARLAB WinRAR contains a Path Traversal vulnerability, allowing an attacker to execute code as the current user.
    • [CVE-2025-62221] Microsoft Windows Use After Free Vulnerability (CVSS v3.1: 7.8)
    • [Exploited by Ransomware: Unknown] Microsoft Windows Cloud Files Mini Filter Driver contains a Use After Free vulnerability that may allow an authenticated attacker to elevate privileges locally.
    • [CVE-2025-58360] OSGeo GeoServer Improper Restriction of XML External Entity Reference Vulnerability (CVSS v3.1: 8.2)
    • [Exploited by Ransomware: Unknown] OSGeo GeoServer contains an Improper Restriction of XML External Entity Reference vulnerability. When the application receives XML input for the GetMap operation on the /geoserver/wms endpoint, it may allow an attacker to define external entities in the XML request.
    • [CVE-2018-4063] Sierra Wireless AirLink ALEOS Unrestricted Upload of File with Dangerous Type Vulnerability (CVSS v3.1: 8.8)
    • [Exploited by Ransomware: Unknown] Sierra Wireless AirLink ALEOS contains an Unrestricted Upload of File with Dangerous Type vulnerability. An attacker can upload files via a specially crafted HTTP request, leading to the upload of executable code to the Web server, which can then be accessed over the network.
    • The attacker only needs to send an authenticated HTTP request to trigger this vulnerability. Affected products may have reached End-of-Life (EoL) and/or End-of-Service (EoS) status, and users should stop using these products.
    • [CVE-2025-14174] Google Chromium Out of Bounds Memory Access Vulnerability (CVSS v3.1: 8.8)
    • [Exploited by Ransomware: Unknown] Google Chromium's ANGLE component contains an Out of Bounds Memory Access vulnerability, which may allow a remote attacker to perform out-of-bounds memory access via a specially crafted HTML page. This vulnerability may affect multiple web browsers that use Chromium, including but not limited to Google Chrome, Microsoft Edge, and Opera.
  • Affected Platforms:
  • Recommended Actions:

Computer and Communication Center
Network Systems Division, Respectfully