A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to add the Carriage Return and Line Feed (CRLF) control characters and include arbitrary SMTP headers in the generated test email.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HAxis Os
OSAxis< 10.7Axis Os 2016
OSAxis< 6.50.5.5Axis Os 2018
OSAxis< 8.40.4.3Axis Os 2020
OSAxis< 9.80.3.5
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Powiązane podatności
CVE-2025-0324CRITICAL9.4PL ✓ten sam produkt
Privilege escalation w VAPIX Device Configuration Framework (Axis OS)
CVE-2023-21413CRITICAL9.1PL ✓ten sam produkt
Command Injection w AXIS OS podczas instalacji aplikacji ACAP — RCE
CVE-2025-11142HIGH7.1ten sam produkt
The VAPIX API mediaclip.cgi that did not have a sufficient input validation allowing for a possible remote cod...
CVE-2025-0358HIGH8.8ten sam produkt
During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the ...
CVE-2025-0359HIGH8.5ten sam produkt
During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the ...