CVE-2025-3892 Details
Description
ACAP applications can be executed with elevated privileges, potentially leading to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.
A vulnerability exists in Axis devices running AXIS OS versions 12.0.0 through 12.5.30, allowing ACAP applications to be executed with elevated privileges. This could lead to unauthorized privilege escalation. The vulnerability can be exploited only if the device is set to permit the installation of unsigned ACAP applications, and if an attacker persuades a user to install a malicious ACAP application.
Axis has released a patch for this vulnerability in AXIS OS Active Track 12.5.31. For devices not included in this track but still under support, patches will be provided according to the planned maintenance and release schedule. Users are advised to update their Axis device software to the latest version available.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 14, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.axis.com/dam/public/ae/19/16/cve-2025-3892pdf-en-US-492760.pdf | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-250 | Execution with Unnecessary Privileges | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| axis axis os | >= 12.0.0, < 12.5.31 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 13, 2026 | Initial Analysis | [email protected] |
| Aug 12, 2025 | New CVE Received | [email protected] |