CVE-2025-0358

During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework that allowed a privilege escalation, enabling a lower-privileged user to gain administrator privileges.
Configurations

Configuration 1 (hide)

cpe:2.3:o:axis:axis_os:*:*:*:*:active:*:*:*

History

15 Jan 2026, 15:27

Type Values Removed Values Added
Summary
  • (es) Durante una prueba de penetración anual realizada en nombre de Axis Communication, Truesec descubrió una falla en el marco de configuración del dispositivo VAPIX que permitía una escalada de privilegios, lo que permitió que un usuario con menores privilegios obtuviera privilegios de administrador.
CWE NVD-CWE-noinfo
CPE cpe:2.3:o:axis:axis_os:*:*:*:*:active:*:*:*
First Time Axis axis Os
Axis
References () https://www.axis.com/dam/public/35/90/85/cve-2025-0358pdf-en-US-483809.pdf - () https://www.axis.com/dam/public/35/90/85/cve-2025-0358pdf-en-US-483809.pdf - Vendor Advisory

02 Jun 2025, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-02 08:15

Updated : 2026-01-15 15:38


NVD link : CVE-2025-0358

Mitre link : CVE-2025-0358

CVE.ORG link : CVE-2025-0358


JSON object : View

Products Affected

axis

  • axis_os
CWE
CWE-269

Improper Privilege Management

NVD-CWE-noinfo