CVE-2025-0324

The VAPIX Device Configuration framework allowed a privilege escalation, enabling a lower-privileged user to gain administrator privileges.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:axis:axis_os:*:*:*:*:active:*:*:*
cpe:2.3:o:axis:axis_os_2024:*:*:*:*:lts:*:*:*

History

15 Jan 2026, 15:42

Type Values Removed Values Added
First Time Axis axis Os
Axis axis Os 2024
Axis
CPE cpe:2.3:o:axis:axis_os:*:*:*:*:active:*:*:*
cpe:2.3:o:axis:axis_os_2024:*:*:*:*:lts:*:*:*
Summary
  • (es) El framework de VAPIX Device Configuration permitió una escalada de privilegios, haciendo posible que un usuario con menores privilegios obtuviera permisos de administrador.
References () https://www.axis.com/dam/public/04/f3/1c/cve-2025-0324pdf-en-US-483807.pdf - () https://www.axis.com/dam/public/04/f3/1c/cve-2025-0324pdf-en-US-483807.pdf - Vendor Advisory

02 Jun 2025, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-02 08:15

Updated : 2026-01-15 15:42


NVD link : CVE-2025-0324

Mitre link : CVE-2025-0324

CVE.ORG link : CVE-2025-0324


JSON object : View

Products Affected

axis

  • axis_os_2024
  • axis_os
CWE
CWE-791

Incomplete Filtering of Special Elements