CVE-2025-29269: Allnet All-RUT22GW Firmware
Critical severity, CVSS 9.8. EPSS: 2% chance of exploitation in the next 30 days.
ALLNET ALL-RUT22GW v3.3.8 was discovered to contain an OS command injection vulnerability via the command parameter in the popen.cgi endpoint.
Affected products
- Allnet All-RUT22GW Firmware: version 3.3.8 only
Published 2025-12-04. Last modified 2026-07-05.