CVE-2025-4645: Input Validation
An ACAP configuration file lacked sufficient input validation, which could allow for arbitrary code execution. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4645?
CVE-2025-4645 is a high severity vulnerability due to the potential for arbitrary code execution.
How can I mitigate CVE-2025-4645?
To mitigate CVE-2025-4645, ensure that the installation of unsigned ACAP applications is disabled on Axis devices.
What devices are affected by CVE-2025-4645?
CVE-2025-4645 affects various Axis OS devices within version range 12.0.0 to 12.6.7.
How does CVE-2025-4645 allow attackers to exploit it?
CVE-2025-4645 can be exploited if an attacker convinces a user to install a malicious unsigned ACAP application.
Is there a patch available for CVE-2025-4645?
Yes, Axis has released updates to address CVE-2025-4645; installing the latest firmware will mitigate the vulnerability.