CVE-2025-14432

Severity CVSS v4.0:
HIGH
Type:
CWE-532 Information Exposure Through Log Files
Publication date:
16/12/2025
Last modified:
18/12/2025

Description

In limited scenarios, sensitive data might be written to the log file if an admin uses Microsoft Teams Admin Center (TAC) to make device configuration changes. The affected log file is visible only to users with admin credentials. This is limited to Microsoft TAC and does not affect configuration changes made using the provisioning server or the device WebUI.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:hp:poly_videoos:*:*:*:*:*:*:*:* 4.6.1-444242 (excluding)
cpe:2.3:h:hp:poly_eagleeye_cube:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:poly_eagleeye_iv:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:poly_studio_a2:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:poly_studio_e60:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:poly_studio_e70:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:poly_studio_g62:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:poly_studio_g7500:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:poly_studio_usb:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:poly_studio_x30:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:poly_studio_x32:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:poly_studio_x50:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:poly_studio_x52:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:poly_studio_x70:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:poly_studio_x72:-:*:*:*:*:*:*:*