HOMEVULNERABILITIESCVE-2025-62862
MEDIUM

CVE-2025-62862

CWE-125Published: December 16, 2025· Updated: Jun 17, 2026

4.6
CVSS v3.1

Official Description

Ampere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4.5.1 allow an incorrectly formed SMC call to UEFI-MM Boot Error Record Table driver that could result in (1) an out-of-bounds read which leaks Secure-EL0 information to a process running in Non-Secure state or (2) an out-of-bounds write which corrupts Secure or Non-Secure memory, limited to memory mapped to UEFI-MM Secure Partition by the Secure Partition Manager.

NVD Source

Technical Analysis

CVE-2025-62862 requires local access, meaning attackers must already have a foothold on the target system.

Exploitation requires high privileges, which limits the exposure to scenarios where an attacker has already gained initial access.

The vulnerability has a "Changed" scope, meaning successful exploitation can impact components beyond the vulnerable component itself — such as the host operating system or adjacent services.

CVSS v3.1 Vector Breakdown

Exploitability
Attack VectorLocal
Attack ComplexityLow
Privileges Req.High
User InteractionNone
ScopeChanged
Impact
ConfidentialityNone
IntegrityLow
AvailabilityLow
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:L

Affected Vendors & Products

amperecomputing26 product(s)
ampereone a192-32m firmwareampereone a192-32mampereone a192-26m firmwareampereone a192-26mampereone a160-28m firmwareampereone a160-28mampereone a144-33m firmwareampereone a144-33mampereone a144-26m firmwareampereone a144-26mampereone a96-36m firmwareampereone a96-36m+14
Source: NVD CPE · 26 total CPE entries

Exploit & PoC Resources

NO KNOWN EXPLOITNo public exploit confirmed at this time
External links open in a new tab. Always verify in a controlled environment before use.

Official Patches & Advisories

All References (2)

Quick Facts

CVE IDCVE-2025-62862
CVSS Score4.6 / 10
SeverityMEDIUM
WeaknessCWE-125
CISA KEVNo
Affected1 vendor(s)
PublishedDec 16, 2025

Related CVEs (CWE-125)

Recommended Actions

  • Apply vendor patches immediately
  • Monitor CVE-2025-62862 in threat intel feeds
  • Review IDS/IPS signatures for exploitation attempts
Data sourced from NVD (NIST), CISA KEV, and EPSS (FIRST). Analysis generated by CTIWatch. CVE data is provided under the NVD usage policy.