CVE-2025-6026

An improper certificate validation vulnerability was reported in the Lenovo Universal Device Client (UDC) that could allow a user capable of intercepting network traffic to obtain application metadata, including device information, geolocation, and telemetry data.
Configurations

No configuration.

History

21 Oct 2025, 13:15

Type Values Removed Values Added
Summary (en) An improper certificate validation vulnerability was reported in the Lenovo Universal Device Client (UDC) that could allow a user capable of intercepting network traffic to obtain encrypted application metadata, including device information, geolocation, and telemetry data. (en) An improper certificate validation vulnerability was reported in the Lenovo Universal Device Client (UDC) that could allow a user capable of intercepting network traffic to obtain application metadata, including device information, geolocation, and telemetry data.

15 Oct 2025, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-15 15:16

Updated : 2025-10-21 13:15


NVD link : CVE-2025-6026

Mitre link : CVE-2025-6026

CVE.ORG link : CVE-2025-6026


JSON object : View

Products Affected

No product.

CWE
CWE-295

Improper Certificate Validation