VYPR
High severity7.1NVD Advisory· Published Feb 10, 2026· Updated Jun 17, 2026

CVE-2025-11142

CVE-2025-11142

Description

The VAPIX API mediaclip.cgi that did not have a sufficient input validation allowing for a possible remote code execution. This flaw can only be exploited after authenticating with an operator- or administrator- privileged service account.

Affected products

3
  • Axis/AXIS OS2 versions
    cpe:2.3:o:axis:axis_os:*:*:*:*:active:*:*:*+ 1 more
    • cpe:2.3:o:axis:axis_os:*:*:*:*:active:*:*:*range: >=12.6.54,<12.7.36
    • (no CPE)range: 12.6.54
  • Axis/VAPIX APIllm-fuzzy

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.