Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

InsydeH2O — Vulnerabilities & Security Advisories 12

All 12 CVE vulnerabilities found in InsydeH2O, with AI-generated Chinese analysis, references, and POCs.

Vendor: Insyde Software

CVE IDTitleCVSSSeverityPublished
CVE-2026-6484 Lack of verified boot to certain FV may cause arbitrary code execution CWE-1277 8.2 High2026-08-12
CVE-2025-10451 H19Int15CallbackSmm: SMM memory corruption vulnerability in combined DXE/SMM (SMRAM write) CWE-787 8.2 High2025-12-12
CVE-2025-4410 SetupUtility: A buffer overflow vulnerability leads to arbitrary code execution. CWE-20 7.5 High2025-08-13
CVE-2025-4277 Tcg2Smm: improper input validation may lead to arbitrary code execution CWE-20 7.5 High2025-08-13
CVE-2025-4276 UsbCoreDxe: improper input validation may lead to arbitrary code execution CWE-20 7.5 High2025-08-13
CVE-2025-4426 SetupAutomationSmm : SMRAM memory contents leak / information disclosure vulnerability in SMM module CWE-200 6.0 Medium2025-07-30
CVE-2025-4425 SetupAutomationSmm: Stack overflow vulnerability in SMI handler CWE-121 8.2 High2025-07-30
CVE-2025-4424 SetupAutomationSmm : Arbitrary calls to SmmSetVariable with unsanitised arguments in SMI handler CWE-20 6.0 Medium2025-07-30
CVE-2025-4423 SetupAutomationSmm:Vulnerability in the SMM module allow attacker to write arbitrary code and lead to memory corruption CWE-119 8.2 High2025-07-30
CVE-2025-4422 EfiSmiServices : EfiPcdProtocol, SMM memory corruption vulnerabilities in SMM module CWE-787 8.2 High2025-07-30
CVE-2025-4421 EfiSmiServices: gEfiSmmCpuProtocol, SMM memory corruption vulnerabilities in SMM module CWE-787 8.2 High2025-07-30
CVE-2025-4275 SecureFlashDxe: Incorrect UEFI variable attributes check allows usage of invalid certificate 7.8 High2025-06-11

All 12 known CVE vulnerabilities affecting InsydeH2O with full Chinese analysis, references, and POCs where available.