CVE-2025-8108: Input Validation
An ACAP configuration file has improper permissions and lacks input validation, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8108?
CVE-2025-8108 has a high severity rating due to its potential for privilege escalation.
How do I fix CVE-2025-8108?
To fix CVE-2025-8108, ensure proper permissions are set for the ACAP configuration file and disable the installation of unsigned ACAP applications.
Who is affected by CVE-2025-8108?
CVE-2025-8108 affects Axis devices that are configured to allow unsigned ACAP applications.
What type of attack can exploit CVE-2025-8108?
CVE-2025-8108 can be exploited through privilege escalation if an attacker convinces a victim to install a malicious ACAP application.
Is user intervention required for CVE-2025-8108 exploitation?
Yes, user intervention is required as the attacker must convince the victim to install the unsigned ACAP application.