216.73.217.22

CVE-2025-35978

· Published 12/06/2025 06:15 · Modified 12/06/2025 16:06

Labels: CVE-2025-35978 2025-06-12CVE-2025-35978CWE-923[email protected]

Essential information

Published
12/06/2025 06:15
Modified
12/06/2025 16:06
Author
Creator
CVSS
6.9 MEDIUM (v3) 6.9 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Improper restriction of communication channel to intended endpoints issue exists in UpdateNavi V1.4 L10 to L33 and UpdateNaviInstallService Service 1.2.0091 to 1.2.0125. If a local authenticated attacker send malicious data, an arbitrary registry value may be modified or arbitrary code may be executed.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
update navi / update navi cpe:2.3:a:update_navi:update_navi:1.4.L10-1.4.L33:*:*:*:*:*:*:*
update navi / update naviinstallservice cpe:2.3:a:update_navi:update_naviinstallservice:1.2.0091-1.2.0125:*:*:*:*:*:*:*

References