Back to Database
Status published
Medium
CVE-2025-0858
Certain Poly Devices – Path Traversal Vulnerability - Arbitrary File Access by Unauthorized User
Vulnerability Description
A vulnerability was discovered in the firmware builds up to 8.2.1.0820 in certain Poly devices. The firmware flaw does not properly prevent path traversal and could lead to information disclosure.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-0858
Credits & Attribution
No credits recorded in the NVD database.
More from HP, Inc.
View All →CVE-2025-43491
Poly Lens Desktop Application – Privilege Escalation
High
7.3
CVE-2025-43490
HP Hotkey Support – Escalation of Privilege
High
8.4
CVE-2025-43026
HP Support Assistant – Potential Escalation of Privilege
High
7.1
CVE-2025-43023
HP Linux Imaging and Printing Software - Use of DSA Key
Medium
5.9
CVE-2025-43018
Certain HP LaserJet Pro Printers – Potential Information Disclosure
Medium
6.9
Affected Vendor
HP, Inc.
View all reports →Affected Software
Certain Poly Devices
Vulnerable Versions:
See HP security bulletin reference for affected versions
Timeline
Official Publish:
February 5th, 2025
Last Modified:
March 27th, 2025
Added to House:
July 22nd, 2026