Insufficient Access Control in Intel Ethernet Firmware
CVE-2025-27535

5.6MEDIUM

Key Information:

Vendor

Intel

Vendor
CVE Published:
10 February 2026

What is CVE-2025-27535?

The vulnerability in Intel Ethernet Connection E825-C firmware arises from exposed ioctl with insufficient access control. This may allow a privileged user to exploit the system's firmware, potentially leading to a denial of service. For attack success, local access is required, facilitating unauthorized operations without the need for user interaction. Although the vulnerability does not compromise data confidentiality or integrity, it significantly threatens the availability of affected systems, which could disrupt operations and services.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Intel(R) Ethernet Connection E825-C. before version NVM ver. 3.84

References

CVSS V4

Score:
5.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.