CVE-2025-48515: AMD Ryzen 4000 Series Desktop Processors

Medium severity, CVSS 5.4. EPSS: 0.1% chance of exploitation in the next 30 days.

Insufficient parameter sanitization in AMD Secure Processor (ASP) Boot Loader could allow an attacker with access to SPIROM upgrade to overwrite the memory, potentially resulting in arbitrary code execution.

Affected products

  • AMD AMD Ryzen 4000 Series Desktop Processors
  • AMD AMD Ryzen 4000 Series Mobile Processors With Radeon Graphics
  • AMD AMD Ryzen 5000 Series Desktop Processors With Radeon Graphics
  • AMD AMD Ryzen 5000 Series Mobile Processors With Radeon Graphics
  • AMD AMD Ryzen 7030 Series Mobile Processors With Radeon Graphics
  • AMD AMD Ryzen Embedded v2000 Series Processors

Published 2026-02-10. Last modified 2026-06-17.