CVE-2025-4424: Insyde Software INSYDEH2O

Medium severity, CVSS 6.0. EPSS: 0.2% chance of exploitation in the next 30 days.

The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Advisories and Announcements" webpage for more information about the vulnerability.  https://support.lenovo.com/us/en/product_security/home

Affected products

Published 2025-07-30. Last modified 2026-06-17.