CVE-2025-40820

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Affected products do not properly enforce TCP sequence number validation in specific scenarios but accept values within a broad range. This could allow an unauthenticated remote attacker e.g. to interfere with connection setup, potentially leading to a denial of service. The attack succeeds only if an attacker can inject IP packets with spoofed addresses at precisely timed moments, and it affects only TCP-based services.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-940

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-07: 110-07
Full discourse1 post
  • DFIR Lab@DFIR_Lab

    🚨 HIGH: CVE-2025-40820 (CVSS 7.5) TCP sequence validation flaw allows unauthenticated remote DoS via spoofed packets. Affects TCP-based services. Requires precise timing but no authentication. #CVE #Vulnerability #PatchNow https://t.co/3n21fdgqjC

    0000020
    144 followersView on X

Explore more