# Check Point response to CVE-2025-2028

Please read this important update from Check Point.

Security Alert:

**Medium**  
**Product**: Other  
**Version**: R81.10 (EOS), R81.20, R82  
**Last Modified**: 2025-11-03

## Symptoms

- Lack of TLS validation when downloading a visualization support data (CSV) file that includes mapping from IP addresses to countries used only for displaying country flags in logs.

This issue received the ID [CVE-2025-2028](https://www.cve.org/CVERecord?id=CVE-2025-2028).

## Cause

TLS was used but not validated in this specific case.

## Solution

This problem was fixed.  The fix is included in:

- [Jumbo Hotfix Accumulator for R82](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm) starting from Take 43
- [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 118
- [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 177

Install the Jumbo Hotfix on the Security Management and Logging servers.

## Article Properties

**Access Level**: General  
**Severity**: Medium  
**Status**: Approved  
**Date Created**: 2025-04-14  
**Last Modified**: 2025-11-03
