Vulnerability Details CVE-2025-11142
The VAPIX API mediaclip.cgi that did not have a sufficient input validation allowing for a possible remote code execution. This flaw can only be exploited after authenticating with an operator- or administrator- privileged service account.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 25.6%
CVSS Severity
CVSS v3 Score 7.1
Products affected by CVE-2025-11142
-
cpe:2.3:o:axis:axis_os:12.6.103
-
cpe:2.3:o:axis:axis_os:12.6.104
-
cpe:2.3:o:axis:axis_os:12.6.106
-
cpe:2.3:o:axis:axis_os:12.6.108
-
cpe:2.3:o:axis:axis_os:12.6.69
-
cpe:2.3:o:axis:axis_os:12.6.85
-
cpe:2.3:o:axis:axis_os:12.6.86
-
cpe:2.3:o:axis:axis_os:12.6.87
-
cpe:2.3:o:axis:axis_os:12.6.90
-
cpe:2.3:o:axis:axis_os:12.6.94
-
cpe:2.3:o:axis:axis_os:12.6.97
-
cpe:2.3:o:axis:axis_os:12.7.33