CVE-2025-5452

A malicious ACAP application can gain access to admin-level service account credentials used by legitimate ACAP applications, leading to potential privilege escalation of the malicious ACAP application. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAPĀ application.
Configurations

No configuration.

History

11 Nov 2025, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-11 07:15

Updated : 2025-11-12 16:19


NVD link : CVE-2025-5452

Mitre link : CVE-2025-5452

CVE.ORG link : CVE-2025-5452


JSON object : View

Products Affected

No product.

CWE
CWE-214

Invocation of Process Using Visible Sensitive Information