CVE-2025-0361

Publication date

2025-04-08 05:38:02

Family

Axis

State

PUBLISHED

Description

During an annual penetration test conducted on behalf of Axis Communications, Truesec discovered a flaw in the VAPIX Device Configuration framework that allowed for unauthenticated username enumeration through the VAPIX Device Configuration SSH Management API.