CVE-2025-54510Disclosure

LOWCVSS 5.9 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: High priority (within 72h)

NVD description

A missing lock verification in AMD Secure Processor (ASP) firmware may permit a locally authenticated attacker with administrative privileges to alter MMIO routing on some Zen 5-based products, potentially compromising guest system integrity.

2.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-414

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 9 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • False Positive: 2 classified signals
  • Peaked 5d ago at 2 mentions (2026-04-14); latest day: 1
  • 9 total mentions across 6 days

Deep dive

Activity timeline9 mentions / 6d
01122Mentions · 2026-04-14: 2Mentions · 2026-04-16: 1Mentions · 2026-04-17: 2Mentions · 2026-04-20: 2Mentions · 2026-05-19: 1Mentions · 2026-05-22: 1Exploit Tool / Code · 2026-04-16: 1Patch / Workaround · 2026-04-14: 1Patch / Workaround · 2026-04-16: 1Patch / Workaround · 2026-04-20: 1Patch / Workaround · 2026-05-19: 1Technical Details · 2026-04-16: 1Technical Details · 2026-04-17: 1Technical Details · 2026-04-20: 2Technical Details · 2026-05-19: 104-1404-1604-1704-2005-1905-22
Signal classification5 categories
Disclosure
444.4%
False Positive
222.2%
Patch
111.1%
Exploit
111.1%
Discl
111.1%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-142
False Positive1Patch1
2026-04-161
Exploit1
2026-04-172
Disclosure2
2026-04-202
Disclosure2
2026-05-191
Discl1
2026-05-221
False Positive1
Full discourse9 posts
  • 女性声優@ssig33
    False Positive

    CVE-2025-54510、これ「AWSやGoogle Cloudに悪意があればユーザーの秘密計算をのぞける」というものなんだけど、そもそもAWSやGoogleに悪意があればハード改造し放題なわけで、これは本当に脆弱性なのか? 秘密計算というコンセプトが、嘘、ごまかし、詐欺というだけな気がしてくるのだが、、、

    Post summary

    The post expresses skepticism about CVE-2025‑54510, labeling its alleged impact as misinformation and implying the vulnerability does not exist.

    18254126.1K
    11.2K followersView on X
  • draco@p71sm
    False Positive

    @angelroom0 Me when AMD/Intel ship literal spyware into a CPU but le anticheat is the problem and CVE-2025-27708, CVE-2025-54510 are totally normal behavior 👀👀👀👀👀👀👀

    Post summary

    The tweet claims that CVE-2025-27708 and CVE-2025-54510 are normal behavior and therefore not serious security concerns, effectively debunking them as false positives.

    000411.1K
    15 followersView on X
  • Shweta Shinde@shw3ta_shinde
    Patch

    Amazing work with @wech_chris and @BenedictSchluet. To appear at @USENIXSecurity'26 AMD has released patches for CVE-2025-54510

    Post summary

    The text announces that AMD has released patches for CVE‑2025‑54510, with no additional exploitation or PoC details.

    00030293
    1.1K followersView on X
  • JAPAH@japahttv
    Discl

    Pesquisadores da ETH Zurich descobriram a falha Fabricked (CVE-2025-54510) no AMD Infinity Fabric, que permite roubo de dados em máquinas virtuais protegidas por SEV-SNP via hipervisor malicioso. A AMD já lançou patches para Zen 3, 4 e 5. (Fonte: GitHub, ETH Zurich e AMD) https://t.co/rMdIELRRFw

    Post summary

    Researchers at ETH Zurich disclosed the Fabricked flaw (CVE‑2025‑54510) affecting AMD Infinity Fabric, enabling data theft from SEV‑SNP protected VMs via a malicious hypervisor. AMD has already released patches for Zen 3, Zen 4 and Zen 5.

    010101.1K
    1.1K followersView on X
  • Gray Hats@the_yellow_fall
    Disclosure

    ETH Zurich researchers unmasked "Fabricked" (CVE-2025-54510), a flaw in AMD Infinity Fabric that bypasses SEV-SNP memory isolation. Patch your firmware today! #Fabricked #AMD #ConfidentialComputing #CyberSecurity #InfoSec #CloudSecurity #HardwareSecurity https://securityonline.info/fabricked-amd-sev-snp-vulnerability-cve-2025-54510/ https://t.co/VBgYsIhjSP

    Post summary

    ETH Zurich researchers expose a new AMD Infinity Fabric flaw (CVE‑2025‑54510) that bypasses SEV‑SNP memory isolation and recommend patching firmware immediately.

    00001569
    11.3K followersView on X
  • Enigma-Global@EnigmaGlobalSW
    Disclosure

    Intel Report [CRITICAL] - A critical vulnerability designated CVE-2025-54510, dubbed "Fabricked," has been disclosed affecting AMD's Secure Encrypted Virtualization with Secure Nested Paging (SEV-SNP) technology. The attack exploits AMD's Infinity... https://www.enigma-global.com/og/report/cve-2025-54510-fabricked-deterministic-attack-against-amd-sev-snp-confidential-mo7by251-47lu

    Post summary

    The report announces CVE-2025-54510, a critical vulnerability in AMD SEV‑SNP called "Fabricked", detailing its exploitation vectors but does not provide PoC, patch, or active exploitation evidence.

    00000221
    4 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-54510 A missing lock verification in AMD Secure Processor (ASP) firmware may permit a locally authenticated attacker with administrative privileges to alter MMIO routing on… https://www.cve.org/CVERecord?id=CVE-2025-54510

    Post summary

    The entry details a missing lock verification in AMD Secure Processor firmware that could allow privileged local attackers to alter MMIO routing, but no exploitation evidence, PoC, or patch information is provided.

    00000231
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-54510 Missing Lock Verification in AMD Secure Processor Firmwar... https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-54510 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The tweet posts a link to a vulnerability details page for CVE‑2025‑54510, but provides no evidence of an exploit, patch, or active usage.

    00000173
    4.0K followersView on X
  • SecureChap@SecureChap
    Exploit

    Fabricked breaks AMD's SEV-SNP with a malicious hypervisor. CVE-2025-54510 targets Zen 5 EPYC processors confirmed vulnerable; AMD advisory extends to Zen 3 and Zen 4. Researchers Chris Wech, Benedict Schlüter, and Shweta Shinde from ETH Zurich disclosed to AMD on August 3, 2025. Embargo lifted April 14, 2026. Patch available. Requires UEFI privileges for the hypervisor. Step 1: Patch UEFI firmware to bypass Infinity Fabric lockdown API calls. Fabric remains configurable post-SEV-SNP activation. Step 2: Reconfigure Infinity Fabric routing to redirect memory transactions away from the Platform Security Processor (PSP). Step 3: During SNP_INIT, PSP attempts to write the Reverse Map Table (RMP) for Confidential VM access controls. Writes fail on poisoned routes, leaving RMP in insecure defaults. Step 4: Gain arbitrary read/write access to every Confidential VM. SEV-SNP confidentiality and integrity defeated. 100% deterministic, software-only attack. No cooperation from victim VMs required. A trusted coprocessor is only as trusted as the fabric carrying its writes.

    Post summary

    AMD disclosed CVE‑2025‑54510, exposing a software‑only, deterministic vulnerability in SEV‑SNP that can be exploited via a malicious hypervisor; detailed attack steps and a UEFI patch are provided.

    00000354
    6 followersView on X

Explore more