SB2025081128 - Improper access control in Lenovo 510 FHD and Performance FHD web cameras



SB2025081128 - Improper access control in Lenovo 510 FHD and Performance FHD web cameras

Published: August 11, 2025

Security Bulletin ID SB2025081128
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Physical access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper access control (CVE-ID: CVE-2025-4371)

The vulnerability allows an attacker to compromise the affected device.

The vulnerability exists due to improper access restrictions. An attacker with physical access to device can write arbitrary firmware updates to the device over a USB connection.


Remediation

Install update from vendor's website.