PT-2025-46310 · Unknown · Axis Communications

Urcq

·

Published

2025-11-11

·

Updated

2025-11-24

·

CVE-2025-8108

CVSS v3.1

6.7

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Axis Communications (affected versions not specified)
Description An ACAP configuration file has improper permissions and lacks input validation, potentially leading to privilege escalation. Exploitation requires the Axis device to allow the installation of unsigned ACAP applications and an attacker convincing a victim to install a malicious ACAP application.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Incorrect Permission

Weakness Enumeration

Related Identifiers

CVE-2025-8108

Affected Products

Axis Communications