A Guard Tour VAPIX API parameter allowed the use of arbitrary values and can be incorrectly called, allowing an attacker to block access to the guard tour configuration page in the web interface of the Axis device.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-16621 | A Guard Tour VAPIX API parameter allowed the use of arbitrary values and can be incorrectly called, allowing an attacker to block access to the guard tour configuration page in the web interface of the Axis device. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 02 Jun 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 02 Jun 2025 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Guard Tour VAPIX API parameter allowed the use of arbitrary values and can be incorrectly called, allowing an attacker to block access to the guard tour configuration page in the web interface of the Axis device. | |
| Weaknesses | CWE-1287 CWE-628 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Axis
Published:
Updated: 2025-06-02T13:25:19.277Z
Reserved: 2025-01-08T09:38:51.961Z
Link: CVE-2025-0325
Updated: 2025-06-02T13:22:23.523Z
Status : Awaiting Analysis
Published: 2025-06-02T08:15:20.767
Modified: 2025-06-02T17:32:17.397
Link: CVE-2025-0325
No data.
OpenCVE Enrichment
No data.
EUVD