CVE-2025-5454: Input Validation
An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to potential privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5454?
CVE-2025-5454 has been assessed as a high severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2025-5454?
To mitigate CVE-2025-5454, ensure that the Axis device is configured to disallow the installation of unsigned ACAP applications.
What types of attacks can CVE-2025-5454 facilitate?
CVE-2025-5454 can facilitate path traversal attacks leading to privilege escalation.
On which devices does CVE-2025-5454 affect?
CVE-2025-5454 affects Axis devices that allow the installation of unsigned ACAP applications.
What conditions are necessary for exploiting CVE-2025-5454?
Exploitation of CVE-2025-5454 requires that the Axis device is configured to permit unsigned ACAP application installations.