CVE-2025-6230: Lenovo Commercial Vantage

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

A SQL injection vulnerability was reported in Lenovo Vantage that could allow a local attacker to modify the local SQLite database and execute limited SQLite commands.

Affected products

  • Lenovo Commercial Vantage: before 20.2506.39.0 (fixed in 20.2506.39.0)
  • Lenovo Vantage: before 10.2501.20.0 (fixed in 10.2501.20.0)

Published 2025-07-17. Last modified 2026-06-17.