CVE-2025-0325 – Axis Guard Tour VAPIX API Parameter Injection Vulnerability

The following table lists the changes that have been made to the
CVE-2025-0325 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Jun. 02, 2025

    Action Type Old Value New Value
    Added Description A Guard Tour VAPIX API parameter allowed the use of arbitrary values and can be incorrectly called, allowing an attacker to block access to the guard tour configuration page in the web interface of the Axis device.
    Added CVSS V3.1 AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
    Added CWE CWE-628
    Added CWE CWE-1287
    Added Reference https://www.axis.com/dam/public/d0/ae/fe/cve-2025-0325pdf-en-US-483808.pdf
Share the Post:

Related Posts