CVE-2025-11531 describes a path traversal vulnerability in HP System Event Utility and Omen Gaming Hub, allowing unauthorized execution of files outside their intended directories. With a CVSS score of 8.8 (High), this vulnerability presents a significant risk, enabling high impact to confidentiality, integrity, and availability through a low-complexity network attack requiring low privileges. While no active exploitation, public exploit code, or significant community discussion has been observed, HP has released remediated versions (System Event Utility 3.2.12 and Omen Gaming Hub 1101.2511.101.0) to address this flaw.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1101.2511.101.0CPE matchmatch criteria | cpe:2.3:a:hp:omen_gaming_hub:*:*:*:*:*:*:*:* | ||
< 3.2.12CPE matchmatch criteria | cpe:2.3:a:hp:system_event_utility:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.