# CVE-2025-5452

## Summary

- **CVE ID:** CVE-2025-5452
- **Severity:** MEDIUM
- **CVSS Score:** 6.6 (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-214
- **Published:** Nov 11, 2025
- **Last Modified:** Mar 13, 2026

## Description

A malicious ACAP application can gain access to admin-level service account credentials used by legitimate ACAP applications, leading to potential privilege escalation of the malicious ACAP application. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.

## Affected Products

- Axis Communications AB — AXIS OS (12.0.0)

## References

- [CNA](https://www.axis.com/dam/public/39/ba/8b/cve-2025-5452pdf-en-US-504212.pdf)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.29%
- **EPSS Percentile:** 21.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._