CVE-2025-56267

9.8

Avigilon · ACM

A CSV injection vulnerability in the /id_profiles endpoint of Avigilon ACM v7.10.0.20 allows unauthenticated attackers to execute arbitrary code via a crafted Excel file.

Executive summary

A critical CSV injection vulnerability in Avigilon ACM v7.10.0.20 allows unauthenticated remote code execution, posing a severe threat to system integrity.

Vulnerability

The vulnerability exists within the /id_profiles endpoint, where improper sanitization of input allows an unauthenticated attacker to inject malicious commands into a CSV file, resulting in arbitrary code execution.

Business impact

Successful exploitation of this vulnerability grants an attacker full control over the affected system, leading to potential data exfiltration, service disruption, or unauthorized access to physical security management systems. Given the CVSS score of 9.8, this represents a critical risk to business operations and organizational security posture.

Remediation

Immediate Action: Contact the vendor immediately to obtain the latest security update or patch for Avigilon ACM, as no specific version number is provided for the remediation.

Proactive Monitoring: Review web server access logs for suspicious requests directed at the /id_profiles endpoint, specifically looking for unusual payloads or characters associated with CSV injection.

Compensating Controls: Implement a Web Application Firewall (WAF) to inspect and block malicious input at the /id_profiles endpoint until a vendor-supplied patch is successfully deployed.

Exploitation status

Public Exploit Available: Yes — a published proof-of-concept exists, as documented in the technical write-up referenced in the CVE record.

Analyst recommendation

Due to the critical nature of this vulnerability and the availability of public technical details, immediate action is required to secure the affected Avigilon ACM deployment. Administrators should prioritize identifying vulnerable instances and applying vendor-provided mitigations or patches as soon as they become available to prevent unauthorized code execution.

History

  1. Disclosed CVE record published
  2. Published in the daily brief critical section
  3. Published in the daily brief critical section
  4. Look Back published
  5. Analyst report written

Sources