Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-16620 | During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework that allowed a privilege escalation, enabling a lower-privileged user to gain administrator privileges. |
Thu, 15 Jan 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:o:axis:axis_os:*:*:*:*:active:*:*:* |
Mon, 02 Jun 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 02 Jun 2025 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework that allowed a privilege escalation, enabling a lower-privileged user to gain administrator privileges | During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework that allowed a privilege escalation, enabling a lower-privileged user to gain administrator privileges. |
Mon, 02 Jun 2025 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework that allowed a privilege escalation, enabling a lower-privileged user to gain administrator privileges | |
| Weaknesses | CWE-269 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Axis
Published:
Updated: 2025-06-02T12:59:42.360Z
Reserved: 2025-01-09T07:07:32.611Z
Link: CVE-2025-0358
Updated: 2025-06-02T12:59:31.739Z
Status : Analyzed
Published: 2025-06-02T08:15:20.917
Modified: 2026-01-15T15:38:44.697
Link: CVE-2025-0358
No data.
OpenCVE Enrichment
Updated: 2025-06-17T12:08:35Z
EUVD