CVE-2025-0361

During an annual penetration test conducted on behalf of Axis Communications, Truesec discovered a flaw in the VAPIX Device Configuration framework that allowed for unauthenticated username enumeration through the VAPIX Device Configuration SSH Management API.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:axis:axis_os:*:*:*:*:active:*:*:*
cpe:2.3:o:axis:axis_os_2024:*:*:*:*:lts:*:*:*

History

No history.

Information

Published : 2025-04-08 06:15

Updated : 2026-01-14 14:41


NVD link : CVE-2025-0361

Mitre link : CVE-2025-0361

CVE.ORG link : CVE-2025-0361


JSON object : View

Products Affected

axis

  • axis_os
  • axis_os_2024
CWE
CWE-203

Observable Discrepancy