CVE-2025-6026: Lenovo Universal Device Client

Low severity, CVSS 3.1. EPSS: 0.1% chance of exploitation in the next 30 days.

An improper certificate validation vulnerability was reported in the Lenovo Universal Device Client (UDC) that could allow a user capable of intercepting network traffic to obtain application metadata, including device information, geolocation, and telemetry data.

Affected products

  • Lenovo Universal Device Client: before 25.7.0.21 (fixed in 25.7.0.21)

Published 2025-10-15. Last modified 2026-10-08.