Unrated severityNVD Advisory· Published Nov 25, 2025· Updated Feb 26, 2026
CVE-2025-33189
CVE-2025-33189
Description
NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause an out-of-bound write. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, information disclosure, or escalation of privileges.
Affected products
2- NVIDIA/DGX Sparkv5Range: All versions prior to OTA0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3News mentions
0No linked articles in our index yet.