CVE-2025-9524: Axis Communications Ab Axis OS

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The VAPIX API port.cgi did not have sufficient input validation, which may result in process crashes and impact usability. This vulnerability can only be exploited after authenticating with a viewer- operator- or administrator-privileged service account.

Affected products

  • Axis Communications Ab Axis OS: from 6.50.0, before 6.50.5.21 (fixed in 6.50.5.21); from 7.0.0, before 8.40.89 (fixed in 8.40.89); from 9.0.0, before 9.80.123 (fixed in 9.80.123); from 10.0.0, before 10.12.305 (fixed in 10.12.305); from 11.0.0, before 11.11.177 (fixed in 11.11.177); from 12.0.0, before 12.7.11 (fixed in 12.7.11)

Published 2025-11-11. Last modified 2026-06-17.