CVE-2025-0361

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
08/04/2025
Last modified:
14/01/2026

Description

During an annual penetration test conducted on behalf of Axis Communications, Truesec discovered a flaw in the VAPIX Device Configuration framework that allowed for unauthenticated username enumeration through the VAPIX Device Configuration SSH Management API.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:axis:axis_os:*:*:*:*:active:*:*:* 11.11.0 (including) 12.3.56 (excluding)
cpe:2.3:o:axis:axis_os_2024:*:*:*:*:lts:*:*:* 11.11.141 (excluding)