
LOOK BACK — Last September, Avigilon ACM got a 'critical' CSV injection at CVSS 9.8. Eight months later: the real exploit fires when an operator opens an exported CSV in Excel, not on the server. CVE-2025-56267, where the score outran the bug. https://t.co/LOtRgRVKZi
Post summary
The tweet highlights a critical CSV injection flaw in Avigilon ACM (CVE-2025-56267) and explains it can be exploited by opening an exported CSV in Excel, without providing PoC, patch, or evidence of active attacks.
