CVE-2025-0324 is a privilege escalation vulnerability in the VAPIX Device Configuration framework. According to the provided content, the flaw allows a lower-privileged authenticated user to elevate privileges and obtain administrator access. Specific vulnerable functions, code paths, and affected versions are not provided in the available material.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This six-file repository is a defensive verification proof of concept and root-cause analysis for CVE-2025-0324 in Axis Communications AXIS OS VAPIX Device Configuration. Its sole executable, poc/verify_cve_2025_0324.py, is a Python requests-based command-line tool supporting Basic or Digest authentication and HTTP or HTTPS targets. It targets a vulnerable Axis Apache authorization module that trusts Apache's server-name result; with UseCanonicalName disabled, a client-supplied Host header of localhost-acap can cause a valid authenticated session, including a viewer-level account, to obtain all defined administrative roles. Safe mode checks firmware information and compares the response from a protected firewall configuration API with and without the crafted Host header. The optional, explicitly gated intrusive mode demonstrates impact by creating a disposable SSH user through an administrator-only API, then uses separately supplied administrator credentials to remove the user and restore the SSH configuration state. Supporting files are README and security-policy documentation, a PoC usage/safety document, dependency list (requests>=2.31.0), and license. The tool is not tied to Metasploit, Nuclei, or another exploit framework.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.