---
id: CVE-2025-5454
title: >-
  An ACAP configuration file lacked sufficient input validation, which could
  allow a path traversal attack leading to potential privilege escalation
summary: >-
  An ACAP configuration file lacked sufficient input validation, which could
  allow a path traversal attack leading to potential privilege escalation. This
  vulnerability can only be exploited if the Axis device is configured to allow
  the in…
severity: medium
cvss: 6.4
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-35
vendor: axis
product: axis_os
affected:
  - 'axis_os >= 12.0.0, < 12.6.18'
patched:
  - axis_os 12.6.18
published: '2025-11-11'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T21:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-5454'
references:
  - url: 'https://www.axis.com/dam/public/48/ab/82/cve-2025-5454pdf-en-US-504213.pdf'
    label: product-security@axis.com
tags:
  - nvd
epss: 0.00153
epssPercentile: 0.0386
ingestedAt: '2026-10-07T21:54:15.017Z'
---

## Overview

An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to potential privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.

## Affected

- `axis_os >= 12.0.0, < 12.6.18`

## Remediation

Upgrade past the affected range:

- `axis_os 12.6.18`
