CVE-2025-14432

MEDIUM
Published Dec 16, 2025 Modified Dec 18, 2025 CWE-532

Description

In limited scenarios, sensitive data might be written to the log file if an admin uses Microsoft Teams Admin Center (TAC) to make device configuration changes. The affected log file is visible only to users with admin credentials. This is limited to Microsoft TAC and does not affect configuration changes made using the provisioning server or the device WebUI.

CVSS v3.1 Score

4.9
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Weakness Type (CWE)

CWE-532 CWE-532

Affected Products

Vendor Product
hp poly_videoos
hp poly_eagleeye_cube
hp poly_eagleeye_iv
hp poly_studio_a2
hp poly_studio_e60
hp poly_studio_e70
hp poly_studio_g62
hp poly_studio_g7500
hp poly_studio_usb
hp poly_studio_x30
hp poly_studio_x32
hp poly_studio_x50
hp poly_studio_x52
hp poly_studio_x70
hp poly_studio_x72
hp poly_tcos
hp poly_tc10
hp poly_tc8

References

Frequently Asked Questions

What is CVE-2025-14432? +
In limited scenarios, sensitive data might be written to the log file if an admin uses Microsoft Teams Admin Center (TAC) to make device configuration changes. The affected log file is visible only to users with admin credentials. This is limited to Microsoft TAC and does not affect configuration changes made using the provisioning server or the device WebUI. It has a CVSS v3.1 base score of 4.9 (MEDIUM).
How severe is CVE-2025-14432? +
CVE-2025-14432 has a CVSS v3.1 score of 4.9 out of 10, rated MEDIUM. This is a medium-severity vulnerability that should be remediated as part of regular maintenance.
What products are affected by CVE-2025-14432? +
CVE-2025-14432 affects products from hp, specifically: poly_eagleeye_cube, poly_eagleeye_iv, poly_studio_a2, poly_studio_e60, poly_studio_e70, poly_studio_g62, poly_studio_g7500, poly_studio_usb, poly_studio_x30, poly_studio_x32, poly_studio_x50, poly_studio_x52, poly_studio_x70, poly_studio_x72, poly_tc10, poly_tc8, poly_tcos, poly_videoos. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2025-14432? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2025-14432 — free, no signup required.

Start Free Scan