CVE-2025-0325: Axis Communications Ab Axis OS
Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.
A Guard Tour VAPIX API parameter allowed the use of arbitrary values and can be incorrectly called, allowing an attacker to block access to the guard tour configuration page in the web interface of the Axis device.
Affected products
- Axis Communications Ab Axis OS: from 6.50.0, before 6.50.5.21 (fixed in 6.50.5.21); from 7.0.0, before 8.40.74 (fixed in 8.40.74); from 9.0.0, before 9.80.100 (fixed in 9.80.100); from 10.0.0, before 10.12.278 (fixed in 10.12.278); from 11.0.0, before 11.11.142 (fixed in 11.11.142); from 12.0.0, before 12.4.28 (fixed in 12.4.28)
Published 2025-06-02. Last modified 2026-06-17.