CVE-2025-12048

7.5

Lenovo · Scanner Pro

Lenovo Scanner Pro contains an arbitrary file upload vulnerability that may allow remote code execution or unauthorized system control.

Executive summary

Lenovo Scanner Pro is vulnerable to arbitrary file uploads, posing a severe risk of remote code execution and total system compromise.

Vulnerability

This vulnerability is categorized as an unrestricted upload of a file with a dangerous type (CWE-434), which allows an unauthenticated attacker to upload malicious files to the system.

Business impact

The ability to execute arbitrary code on the affected system represents a critical security failure, as it allows attackers to bypass standard access controls and potentially gain full administrative control over the host. With a CVSS score of 7.5, this flaw carries a high severity level that could lead to significant data breaches or the deployment of persistent malware within the corporate network.

Remediation

Immediate Action: Because this product is officially end-of-life and unsupported by Lenovo, the only secure remediation is to immediately discontinue use and remove the software from all systems.

Proactive Monitoring: Review system logs for unauthorized file modifications or the presence of unexpected executable files within the application directory.

Compensating Controls: If immediate removal is not possible, isolate the affected systems from the network using a firewall to prevent access to the vulnerable application interface.

Exploitation status

Public Exploit Available: exploit_available (unknown)

Analyst recommendation

Given that the vendor has officially ceased support for Lenovo Scanner Pro, there will be no security patches released to address this vulnerability. Security teams must prioritize the immediate decommissioning and removal of this software from all production environments to eliminate the risk of exploitation.

More Lenovo CVEs

Sources