CVE-2025-0325 is a medium-severity vulnerability affecting Axis devices, where an improper VAPIX API parameter in the Guard Tour function allows an authenticated attacker to block access to the guard tour configuration page. The attack requires low privileges and network access, resulting in a low impact on availability (CVSS 4.3). There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Axis Communications AB | AXIS OS | >= 10.0.0, < 10.12.278, >= 11.0.0, < 11.11.142, >= 12.0.0, < 12.4.28, >= 6.50.0, < 6.50.5.21, >= 7.0.0, < 8.40.74, >= 9.0.0, < 9.80.100CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.