CVE-2025-4371

MEDIUM

Lenovo 510 FHD - Privilege Escalation

Title source: llm
STIX 2.1

Description

A potential vulnerability was reported in the Lenovo 510 FHD and Performance FHD web cameras that could allow an attacker with physical access to write arbitrary firmware updates to the device over a USB connection.

Scores

CVSS v3 6.8
EPSS 0.0002
EPSS Percentile 4.3%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-347
Status published
Products (2)
Lenovo/510 FHD Webcam < 4.8.0
Lenovo/Performance FHD Webcam < 4.8.0
Published Aug 18, 2025
Tracked Since Feb 18, 2026