CVE-2025-5452: Medium severity Axis AXIS OS vulnerability
A malicious ACAP application can gain access to admin-level service account credentials used by legitimate ACAP applications, leading to potential privilege escalation of the malicious ACAP application. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5452?
CVE-2025-5452 is classified as a high-severity vulnerability due to the potential for privilege escalation.
How do I fix CVE-2025-5452?
To mitigate the risks associated with CVE-2025-5452, ensure that your Axis device firmware is updated to the latest version that patches this vulnerability.
What types of applications are affected by CVE-2025-5452?
CVE-2025-5452 affects malicious ACAP applications that can gain unauthorized access to admin-level service account credentials.
Is CVE-2025-5452 easily exploitable?
CVE-2025-5452 can only be exploited if the Axis device is configured to allow the installation of potentially harmful ACAP applications.
Which Axis devices are vulnerable to CVE-2025-5452?
CVE-2025-5452 affects various Axis devices running vulnerable versions of the Axis OS between 12.0.0 and 12.6.69.