CVE-2025-0325
A Guard Tour VAPIX API parameter allowed the use of arbitrary values and can be incorrectly called, allowing an attacker to block access to the guard tour configuration page in the web interface of the Axis device.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
- EPSS probability
- 0.38%
- CWE
- CWE-1287, CWE-628
- Published
- 2025-06-02
- Last modified
- 2026-03-13
Affected products
- Axis Communications AB AXIS OS
- Axis Communications AB AXIS OS
- Axis Communications AB AXIS OS
- Axis Communications AB AXIS OS
- Axis Communications AB AXIS OS
- Axis Communications AB AXIS OS
Weakness type
Related vulnerabilities
- CVE-2026-87012 — Open WebUI: Any authenticated user can suppress calendar alerts instance-wide via a non-numeric alert value
- CVE-2026-86287 — Net::IP::LPM versions before 1.12 for Perl accept malformed prefix lengths
- CVE-2026-52763 — YesWiki: SQL injection via the `recentchanges` action `period` argument leading to arbitrary DB read
- CVE-2026-59680 — yast2-users: OS command injection via LDAP-supplied shadowLastChange/shadowExpire attribute
- CVE-2026-82741 — Ash.Type.Union with :map_with_tag does not force the tag on dump, enabling tag confusion
- CVE-2026-80051 — github.com/graphql-go/graphql (GraphQL for Go) through 0.8.1 does not validate that a scalar...
- CVE-2026-17113 — Cri-o: cri-o: unvalidated image env var causes daemon crash
- CVE-2026-5304 — An ACAP configuration file lacks input validation, which could potentially lead to privilege...