cbcvebase.
CVE-2025-4645
published 2025-11-11

CVE-2025-4645: An ACAP configuration file lacked sufficient input validation, which could allow for arbitrary code execution. This vulnerability can only be exploited if the…

PriorityP434medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.14%
4.2th percentile
An ACAP configuration file lacked sufficient input validation, which could allow for arbitrary code execution. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.

Affected

10 ranges
VendorProductVersion rangeFixed in
axisaxis_os>= 12.0.0 < 12.6.712.6.7
axis_communications_abaxis_os>= 12.0.0. < 12.6.712.6.7
msrccbl2_libtiff_4.5.0-1_on_cbl_mariner_2.0
msrccbl2_squashfs-tools_4.5-1_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrccm1_libtiff_4.5.0-1_on_cbl_mariner_1.0
msrccm1_squashfs-tools_4.3-26_on_cbl_mariner_1.0

CVSS provenance

nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.