CVE-2025-2762
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2025-2762 is a local privilege escalation vulnerability affecting CarlinKit CPC200-CCPA devices. This issue arises due to the absence of a properly configured hardware root of trust in the application system-on-chip (SoC). An attacker must initially gain the ability to execute low-privileged code on the target system to exploit this flaw. By leveraging this vulnerability, an attacker can escalate privileges and execute arbitrary code during the boot process. This vulnerability, originally identified as ZDI-CAN-25948, poses a significant risk to affected installations.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Jenkins Software
Affected Vendors
- Jenkins