cbcvebase.
CVE-2025-9524
published 2025-11-11

CVE-2025-9524: The VAPIX API port.cgi did not have sufficient input validation, which may result in process crashes and impact usability. This vulnerability can only be…

PriorityP421medium4.3CVSS 3.1
AVNACLPRLUINSUCNINAL
EPSS
0.25%
16.0th percentile
The VAPIX API port.cgi did not have sufficient input validation, which may result in process crashes and impact usability. This vulnerability can only be exploited after authenticating with a viewer- operator- or administrator-privileged service account.

Affected

6 ranges
VendorProductVersion rangeFixed in
axis_communications_abaxis_os>= 10.0.0 < 10.12.30510.12.305
axis_communications_abaxis_os>= 11.0.0 < 11.11.17711.11.177
axis_communications_abaxis_os>= 12.0.0 < 12.7.1112.7.11
axis_communications_abaxis_os>= 6.50.0 < 6.50.5.216.50.5.21
axis_communications_abaxis_os>= 7.0.0 < 8.40.898.40.89
axis_communications_abaxis_os>= 9.0.0 < 9.80.1239.80.123
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.