CVE-2025-11142: OS Command Injection
The VAPIX API mediaclip.cgi that did not have a sufficient input validation allowing for a possible remote code execution. This flaw can only be exploited after authenticating with an operator- or administrator- privileged service account.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11142?
CVE-2025-11142 is classified as a high severity vulnerability due to its potential to allow remote code execution after authentication.
How can I mitigate CVE-2025-11142?
To mitigate CVE-2025-11142, ensure that all user accounts with operator or administrator privileges are securely configured and limit their access.
What software versions are affected by CVE-2025-11142?
CVE-2025-11142 affects Axis OS versions between 12.6.54 and 12.7.36.
Can CVE-2025-11142 be exploited without authentication?
No, CVE-2025-11142 requires an attacker to authenticate with an operator- or administrator-privileged account before exploitation can occur.
What kind of attacks can CVE-2025-11142 facilitate?
CVE-2025-11142 can facilitate remote code execution attacks, allowing an attacker to execute arbitrary code on the affected system.