CVE-2025-6026

LOW

Lenovo UDC - Info Disclosure

Title source: llm
STIX 2.1

Description

An improper certificate validation vulnerability was reported in the Lenovo Universal Device Client (UDC) that could allow a user capable of intercepting network traffic to obtain application metadata, including device information, geolocation, and telemetry data.

Scores

CVSS v3 3.1
EPSS 0.0001
EPSS Percentile 1.1%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-295
Status published
Products (1)
Lenovo/Universal Device Client < 25.7.0.21
Published Oct 15, 2025
Tracked Since Feb 18, 2026