CVE-2025-64125None▾ SunlitA vulnerability in Nuvation Energy nCloud VPN Service allowed Network Boundary Bridging.This issue affected the nCloud VPN Service and was fixed on 2025-12-1 (December, 2025). End users do not have to take any action to mitigate the issue.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
A vulnerability in Nuvation Energy nCloud VPN Service allowed Network Boundary Bridging.This issue affected the nCloud VPN Service and was fixed on 2025-12-1 (December, 2025). End users do not have to take any action to mitigate the issue.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-64123Critical· 9.8Unintended Proxy or Intermediary vulnerability in Nuvation Energy Multi-Stack Controller (MSC) allows Network Boundary Bridging.This issue affects Multi-Stack Controller (MSC): through and including release 2.5.1.
CVE-2025-48560Medium· 5.5In AndroidManifest.xml, there is a possible way for an app to monitor motion events due to a confused deputy
CVE-2025-48529Medium· 5.5In setRingtoneUri of VoicemailNotificationSettingsUtil.java , there is a possible cross user data leak due to a confused deputy
CVE-2025-36889Medium· 5.5In onCreateTasks of CameraActivity.java, there is a possible permission bypass due to a confused deputy
CVE-2025-48628High· 7.8In validateIconUserBoundary of PrintManagerService.java, there is a possible cross-user image leak due to a confused deputy
CVE-2025-48598Medium· 6.6In multiple locations, there is a possible way to alter the primary user's face unlock settings due to a confused deputy