Description
A potential vulnerability was reported in the Lenovo 510 FHD and Performance FHD web cameras that could allow an attacker with physical access to write arbitrary firmware updates to the device over a USB connection.
Scores
CVSS v3
6.8
EPSS
0.0002
EPSS Percentile
4.3%
Attack Vector
PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-347
Status
published
Products (2)
Lenovo/510 FHD Webcam
< 4.8.0
Lenovo/Performance FHD Webcam
< 4.8.0
Published
Aug 18, 2025
Tracked Since
Feb 18, 2026