CVE-2025-6298: Input Validation
ACAP applications can gain elevated privileges due to improper input validation, potentially leading to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6298?
CVE-2025-6298 is considered a high severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2025-6298?
To fix CVE-2025-6298, ensure that your Axis device does not permit the installation of unsigned ACAP applications.
Who is affected by CVE-2025-6298?
CVE-2025-6298 affects users of Axis devices configured to allow installation of unsigned ACAP applications.
What can exploit CVE-2025-6298?
CVE-2025-6298 can be exploited by attackers who convince victims to install malicious ACAP applications.
What are the implications of CVE-2025-6298?
The implications of CVE-2025-6298 include the potential for attackers to gain elevated privileges on the affected Axis devices.