Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-5454


An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to potential privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.


Security Impact Summary

This vulnerability carries a MEDIUM severity rating with a CVSS v3.1 score of 6.4, requiring local system access to exploit but requires specific conditions to be met without requiring user interaction . The vulnerability impacts confidentiality (data exposure), integrity (unauthorized modifications), and availability (service disruption) for affected systems. Impacting 233 products from axis, from axis, from axis and 230 others, organizations running these solutions should prioritize assessment and patching.

Historical Context

Reported in 2025, this vulnerability emerged during an era marked by increased sophistication in supply chain attacks, cloud infrastructure vulnerabilities, and software-as-a-service (SaaS) security challenges. Security practices during this period emphasized zero-trust architectures, container security, and API protection.


Published

2025-11-11T07:15:34.937

Last Modified

2025-11-24T17:57:25.743

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.4 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-35

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System axis axis_os < 12.6.18 Yes
Hardware axis a1210_\(-b\) - No
Hardware axis a1214 - No
Hardware axis a1601 - No
Hardware axis a1610_\(-b\) - No
Hardware axis a1710-b - No
Hardware axis a1810-b - No
Hardware axis a8207-ve_mk_ii - No
Hardware axis c1110-e - No
Hardware axis c1111-e - No
Hardware axis c1210-e - No
Hardware axis c1211-e - No
Hardware axis c1310-e_mk_ii - No
Hardware axis c1410_mk_ii - No
Hardware axis c1510 - No
Hardware axis c1511 - No
Hardware axis c1610-ve - No
Hardware axis c1710 - No
Hardware axis c1720 - No
Hardware axis c6110 - No
Hardware axis c8110 - No
Hardware axis c8210 - No
Hardware axis d1110 - No
Hardware axis d201-s_xpt_q6075 - No
Hardware axis d2110-ve - No
Hardware axis d2210-ve - No
Hardware axis d3110_mk_ii - No
Hardware axis d4100-ve_mk_ii - No
Hardware axis d4200-ve - No
Hardware axis d6310 - No
Hardware axis excam_xf_q1785 - No
Hardware axis excam_xpt_q6075 - No
Hardware axis f9104-b_main_unit - No
Hardware axis f9104-b_mk_ii_main_unit - No
Hardware axis f9111-r_mk_ii_main_unit - No
Hardware axis f9111_main_unit - No
Hardware axis f9111_mk_ii_main_unit - No
Hardware axis f9114-b-r_mk_ii_main_unit - No
Hardware axis f9114-b_main_unit - No
Hardware axis f9114-bt - No
Hardware axis f9114_main_unit - No
Hardware axis fa51 - No
Hardware axis fa51-b - No
Hardware axis fa54 - No
Hardware axis i7010-safety - No
Hardware axis i7010-ve - No
Hardware axis i7020 - No
Hardware axis i8016-lve - No
Hardware axis i8116-e - No
Hardware axis i8307-ve - No
Hardware axis m1055-l - No
Hardware axis m1075-l - No
Hardware axis m1135 - No
Hardware axis m1135-e_mk_ii - No
Hardware axis m1137 - No
Hardware axis m1137-e_mk_ii - No
Hardware axis m2035-le - No
Hardware axis m2036-le - No
Hardware axis m3057-plr_mk_ii - No
Hardware axis m3085-v - No
Hardware axis m3086-v - No
Hardware axis m3086-v_mic - No
Hardware axis m3088-v - No
Hardware axis m3125-lve - No
Hardware axis m3126-lve - No
Hardware axis m3128-lve - No
Hardware axis m3215-lve - No
Hardware axis m3216-lve - No
Hardware axis m3905-r - No
Hardware axis m4215-lv - No
Hardware axis m4215-v - No
Hardware axis m4216-lv - No
Hardware axis m4216-v - No
Hardware axis m4218-lv - No
Hardware axis m4218-v - No
Hardware axis m4225-lve - No
Hardware axis m4227-lve - No
Hardware axis m4228-lve - No
Hardware axis m4308-ple - No
Hardware axis m4317-plr - No
Hardware axis m4317-plve - No
Hardware axis m4318-plr - No
Hardware axis m4318-plve - No
Hardware axis m4327-p - No
Hardware axis m4328-p - No
Hardware axis m5000 - No
Hardware axis m5000-g - No
Hardware axis m5074 - No
Hardware axis m5075 - No
Hardware axis m5075-g - No
Hardware axis m5526-e - No
Hardware axis m7104 - No
Hardware axis m7116 - No
Hardware axis p1245_mk_ii - No
Hardware axis p1265_mk_ii - No
Hardware axis p1275_mk_ii - No
Hardware axis p1385 - No
Hardware axis p1385-b - No
Hardware axis p1385-be - No
Hardware axis p1385-e - No
Hardware axis p1387 - No
Hardware axis p1387-b - No
Hardware axis p1387-be - No
Hardware axis p1387-le - No
Hardware axis p1388 - No
Hardware axis p1388-b - No
Hardware axis p1388-be - No
Hardware axis p1388-le - No
Hardware axis p1465-le - No
Hardware axis p1465-le-3 - No
Hardware axis p1467-le - No
Hardware axis p1468-le - No
Hardware axis p1468-xle - No
Hardware axis p1475-le - No
Hardware axis p1518-e - No
Hardware axis p1518-le - No
Hardware axis p3265-lv - No
Hardware axis p3265-lve - No
Hardware axis p3265-lve-3 - No
Hardware axis p3265-v - No
Hardware axis p3267-lv - No
Hardware axis p3267-lve - No
Hardware axis p3267-lve_mic - No
Hardware axis p3268-lv - No
Hardware axis p3268-lve - No
Hardware axis p3268-slve - No
Hardware axis p3275-lv - No
Hardware axis p3275-lve - No
Hardware axis p3277-lv - No
Hardware axis p3277-lve - No
Hardware axis p3278-lv - No
Hardware axis p3278-lve - No
Hardware axis p3285-lv - No
Hardware axis p3285-lve - No
Hardware axis p3287-lv - No
Hardware axis p3287-lve - No
Hardware axis p3288-lv - No
Hardware axis p3288-lve - No
Hardware axis p3735-ple - No
Hardware axis p3737-ple - No
Hardware axis p3738-ple - No
Hardware axis p3747-plve - No
Hardware axis p3748-plve - No
Hardware axis p3818-pve - No
Hardware axis p3827-pve - No
Hardware axis p3905-r_mk_iii - No
Hardware axis p3925-lre - No
Hardware axis p3925-r - No
Hardware axis p3935-lr - No
Hardware axis p4705-plve - No
Hardware axis p4707-plve - No
Hardware axis p4708-plve - No
Hardware axis p5654-e - No
Hardware axis p5654-e_mk_ii - No
Hardware axis p5655-e - No
Hardware axis p5676-le - No
Hardware axis p7304 - No
Hardware axis p7316 - No
Hardware axis p9117-pv - No
Hardware axis q1615-le_mk_iii - No
Hardware axis q1615_mk_iii - No
Hardware axis q1656 - No
Hardware axis q1656-b - No
Hardware axis q1656-be - No
Hardware axis q1656-ble - No
Hardware axis q1656-dle - No
Hardware axis q1656-le - No
Hardware axis q1686-dle - No
Hardware axis q1715 - No
Hardware axis q1728 - No
Hardware axis q1728-le - No
Hardware axis q1798-le - No
Hardware axis q1800-le - No
Hardware axis q1800-le-3 - No
Hardware axis q1805-le - No
Hardware axis q1806-le - No
Hardware axis q1808-le - No
Hardware axis q1809-le - No
Hardware axis q1961-te - No
Hardware axis q1961-xte - No
Hardware axis q1971-e - No
Hardware axis q1972-e - No
Hardware axis q2101-te - No
Hardware axis q2111-e - No
Hardware axis q2112-e - No
Hardware axis q3536-lve - No
Hardware axis q3538-lve - No
Hardware axis q3538-slve - No
Hardware axis q3546-lve - No
Hardware axis q3548-lve - No
Hardware axis q3556-lve - No
Hardware axis q3558-lve - No
Hardware axis q3626-ve - No
Hardware axis q3628-ve - No
Hardware axis q3819-pve - No
Hardware axis q3839-pve - No
Hardware axis q3839-spve - No
Hardware axis q4809-pve - No
Hardware axis q6020-e - No
Hardware axis q6074 - No
Hardware axis q6074-e - No
Hardware axis q6075 - No
Hardware axis q6075-e - No
Hardware axis q6075-s - No
Hardware axis q6075-se - No
Hardware axis q6078-e - No
Hardware axis q6135-le - No
Hardware axis q6225-le - No
Hardware axis q6300-e - No
Hardware axis q6315-le - No
Hardware axis q6318-le - No
Hardware axis q6355-le - No
Hardware axis q6358-le - No
Hardware axis q8615-e - No
Hardware axis q8752-e - No
Hardware axis q8752-e_mk_ii - No
Hardware axis q9307-lv - No
Hardware axis s3008 - No
Hardware axis s3008_mk_ii - No
Hardware axis s3016 - No
Hardware axis s4000 - No
Hardware axis v5925 - No
Hardware axis v5938 - No
Hardware axis w100 - No
Hardware axis w101 - No
Hardware axis w102 - No
Hardware axis w110 - No
Hardware axis w120 - No
Hardware axis w401 - No
Hardware axis xc1311 - No
Hardware axis xf40-q1785 - No
Hardware axis xfq1656 - No
Hardware axis xpq1785 - No

References

How SecUtils Interprets This CVE

SecUtils normalizes and enriches National Vulnerability Database (NVD) records by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and providing structured context for security teams. For axis's affected products, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference data to enable rapid vulnerability prioritization and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and security operations.