CVE-2025-6026: Lenovo Universal Device Client
Low severity, CVSS 3.1. EPSS: 0.1% chance of exploitation in the next 30 days.
An improper certificate validation vulnerability was reported in the Lenovo Universal Device Client (UDC) that could allow a user capable of intercepting network traffic to obtain application metadata, including device information, geolocation, and telemetry data.
Affected products
- Lenovo Universal Device Client: before 25.7.0.21 (fixed in 25.7.0.21)
Published 2025-10-15. Last modified 2026-10-08.