CVE-2025-10495

HIGH

Lenovo App Store, PC Manager, Browser, and Legion Zone - Remote Code Execution via Improper Certificate Validation

Title source: llm
STIX 2.1

Description

A potential vulnerability was reported in the Lenovo PC Manager, Lenovo App Store, Lenovo Browser, and Lenovo Legion Zone client applications that, under certain conditions, could allow an attacker on the same logical network to execute arbitrary code.

References (1)

Core 1
Core References

Scores

CVSS v3 7.5
EPSS 0.0020
EPSS Percentile 9.5%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-295
Status published
Products (4)
Lenovo/App Store < 9.0.2530.1027
Lenovo/Browser < 9.0.6.9111
Lenovo/Legion Zone < 2.0.21
Lenovo/PC Manager < 5.1.140.9262
Published Nov 12, 2025
Tracked Since Feb 18, 2026