VYPR
High severity8.0NVD Advisory· Published Feb 24, 2026· Updated Jun 17, 2026

CVE-2025-33180

CVE-2025-33180

Description

NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could inject a command. A successful exploit of this vulnerability might lead to escalation of privileges.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

8
  • cpe:2.3:o:nvidia:cumulus_linux:*:*:*:*:-:*:*:*+ 4 more
    • cpe:2.3:o:nvidia:cumulus_linux:*:*:*:*:-:*:*:*range: <5.14.0
    • cpe:2.3:o:nvidia:cumulus_linux:*:*:*:*:lts:*:*:*range: >=5.9.0,<5.9.4
    • (no CPE)range: All versions prior to 5.14 (5.13.x, 5.12.x, and older GA versions)
    • (no CPE)range: All versions prior to 5.9.4
    • (no CPE)
  • Nvidia/NVOS3 versions
    cpe:2.3:o:nvidia:nvos:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:nvidia:nvos:*:*:*:*:*:*:*:*range: <25.02.2452
    • (no CPE)range: All versions prior to 25.02.5030
    • (no CPE)

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.