CVE-2025-3892
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
12/08/2025
Last modified:
13/01/2026
Description
ACAP applications can be executed with elevated privileges, potentially leading to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.
Impact
Base Score 3.x
6.70
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:axis:axis_os:*:*:*:*:active:*:*:* | 12.0.0 (including) | 12.5.31 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



