VYPR
Medium severity4.3NVD Advisory· Published Apr 8, 2025· Updated Jun 17, 2026

CVE-2025-0361

CVE-2025-0361

Description

During an annual penetration test conducted on behalf of Axis Communications, Truesec discovered a flaw in the VAPIX Device Configuration framework that allowed for unauthenticated username enumeration through the VAPIX Device Configuration SSH Management API.

Affected products

4

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.