The VAPIX API mediaclip.cgi that did not have a sufficient input validation allowing for a possible remote code execution. This flaw can only be exploited after authenticating with an operator- or administrator- privileged service account.
https://www.axis.com/dam/public/18/0e/90/cve-2025-11142pdf-en-US-519291.pdf