Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Standard on Windows (Nios II Command Shell modules), Altera Quartus Prime Lite on Windows (Nios II Command Shell modules) allows Search Order Hijacking.This issue affects Quartus Prime Standard: from 19.1 through 24.1; Quartus Prime Lite: from 19.1 through 24.1.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 06 Jan 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 06 Jan 2026 22:00:00 +0000

Type Values Removed Values Added
Description Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Standard on Windows (Nios II Command Shell modules), Altera Quartus Prime Lite on Windows (Nios II Command Shell modules) allows Search Order Hijacking.This issue affects Quartus Prime Standard: from 19.1 through 24.1; Quartus Prime Lite: from 19.1 through 24.1.
Title Quartus® Prime Standard and Quartus® Prime Lite Security Advisory
First Time appeared Altera
Altera quartus Prime Lite
Altera quartus Prime Standard
Weaknesses CWE-427
CPEs cpe:2.3:a:altera:quartus_prime_lite:*:*:windows:*:*:*:*:*
cpe:2.3:a:altera:quartus_prime_standard:*:*:windows:*:*:*:*:*
Vendors & Products Altera
Altera quartus Prime Lite
Altera quartus Prime Standard
References
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 5.4, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Altera

Published:

Updated: 2026-01-06T21:49:33.995Z

Reserved: 2025-12-12T21:06:52.874Z

Link: CVE-2025-14625

cve-icon Vulnrichment

Updated: 2026-01-06T21:49:30.331Z

cve-icon NVD

Status : Received

Published: 2026-01-07T12:16:55.637

Modified: 2026-01-07T12:16:55.637

Link: CVE-2025-14625

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses