CVE-2025-5718: Medium severity Axis ACAP Application framework vulnerability
The ACAP Application framework could allow privilege escalation through a symlink attack. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5718?
CVE-2025-5718 is classified as a medium severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2025-5718?
To mitigate CVE-2025-5718, ensure that your Axis device is not configured to allow the installation of unsigned ACAP applications.
What types of attacks are possible with CVE-2025-5718?
CVE-2025-5718 can be exploited through a symlink attack that leads to privilege escalation.
Which software is affected by CVE-2025-5718?
CVE-2025-5718 affects the Axis ACAP Application Framework used in Axis devices.
What is required for an attacker to exploit CVE-2025-5718?
An attacker must convince the victim to install a malicious ACAP application on their Axis device to exploit CVE-2025-5718.