CVE-2025-3892 – Axis ACAP Privilege Escalation Vulnerability

The following table lists the changes that have been made to the
CVE-2025-3892 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Aug. 12, 2025

    Action Type Old Value New Value
    Added Description ACAP applications can be executed with elevated privileges, potentially leading to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.
    Added CVSS V3.1 AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
    Added CWE CWE-250
    Added Reference https://www.axis.com/dam/public/ae/19/16/cve-2025-3892pdf-en-US-492760.pdf
Share the Post:

Related Posts