CVE-2025-35978
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
12/06/2025
Last modified:
12/06/2025
Description
Improper restriction of communication channel to intended endpoints issue exists in UpdateNavi V1.4 L10 to L33 and UpdateNaviInstallService Service 1.2.0091 to 1.2.0125. If a local authenticated attacker send malicious data, an arbitrary registry value may be modified or arbitrary code may be executed.
Impact
Base Score 4.0
6.90
Severity 4.0
MEDIUM
Base Score 3.x
7.10
Severity 3.x
HIGH



