We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-35978



Description

Improper restriction of communication channel to intended endpoints issue exists in UpdateNavi V1.4 L10 to L33 and UpdateNaviInstallService Service 1.2.0091 to 1.2.0125. If a local authenticated attacker send malicious data, an arbitrary registry value may be modified or arbitrary code may be executed.

Reserved 2025-06-10 | Published 2025-06-12 | Updated 2025-06-12 | Assigner jpcert


HIGH: 7.1CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

MEDIUM: 6.9CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N

Problem types

Improper restriction of communication channel to intended endpoints

Product status

V1.4 L10 to L33
affected

Service 1.2.0091 to 1.2.0125
affected

References

azby.fmworld.net/...t/security/information/updatenavi202506/

jvn.jp/en/jp/JVN17860456/

cve.org (CVE-2025-35978)

nvd.nist.gov (CVE-2025-35978)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-35978

Support options

Helpdesk Chat, Email, Knowledgebase