Sensitive Data Exposure in Axis Communications Devices and Solutions
CVE-2025-6571

6MEDIUM

Key Information:

Status
Vendor
CVE Published:
11 November 2025

What is CVE-2025-6571?

A vulnerability has been identified in various products by Axis Communications where a third-party component inadvertently exposes sensitive passwords through process arguments. This situation enables low-privileged users to potentially exploit the system and gain unauthorized access to sensitive credentials, leading to broader security implications.

Affected Version(s)

AXIS OS 12.0.0 < 12.6.66

AXIS OS 11.11.0 < 11.11.169

References

CVSS V3.1

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

URCQ
.
CVE-2025-6571 : Sensitive Data Exposure in Axis Communications Devices and Solutions