Axis
Products
477- 53 CVEs
- 14 CVEs
- 14 CVEs
- 11 CVEs
- 11 CVEs
- 10 CVEs
- 10 CVEs
- 9 CVEs
- 9 CVEs
- 9 CVEs
- 8 CVEs
- 8 CVEs
- 8 CVEs
- 8 CVEs
- 8 CVEs
- 8 CVEs
- 8 CVEs
- 8 CVEs
- 8 CVEs
- 8 CVEs
- 8 CVEs
- 8 CVEs
- 8 CVEs
- 7 CVEs
- 7 CVEs
- 7 CVEs
- 7 CVEs
- 7 CVEs
- 7 CVEs
- 7 CVEs
- View all 477 products →
Recent CVEs
122| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-10661 | Cri | 0.74 | 9.8 | 0.87 | Jun 26, 2018 | An issue was discovered in multiple models of Axis IP Cameras. There is a bypass of access control. | ||
| CVE-2018-10662 | Cri | 0.73 | 9.8 | 0.80 | Jun 26, 2018 | An issue was discovered in multiple models of Axis IP Cameras. There is an Exposed Insecure Interface. | ||
| CVE-2018-10660 | Cri | 0.73 | 9.8 | 0.82 | Jun 26, 2018 | An issue was discovered in multiple models of Axis IP Cameras. There is Shell Command Injection. | ||
| CVE-2025-30026 | Cri | 0.64 | 9.8 | 0.01 | Jul 11, 2025 | The AXIS Camera Station Server had a flaw that allowed to bypass authentication that is normally required. | ||
| CVE-2017-20049 | Cri | 0.64 | 9.8 | 0.02 | Jun 15, 2022 | A vulnerability, was found in legacy Axis devices such as P3225 and M3005. This affects an unknown part of the component CGI Script. The manipulation leads to improper privilege management. It is possible to initiate the attack remotely. | ||
| CVE-2015-8257 | Hig | 0.62 | 8.8 | 0.18 | May 2, 2017 | The devtools.sh script in AXIS network cameras allows remote authenticated users to execute arbitrary commands via shell metacharacters in the app parameter to (1) app_license.shtml, (2) app_license_custom.shtml, (3) app_index.shtml, or (4) app_params.shtml. | ||
| CVE-2025-0324 | Cri | 0.61 | 9.4 | 0.00 | Jun 2, 2025 | The VAPIX Device Configuration framework allowed a privilege escalation, enabling a lower-privileged user to gain administrator privileges. | ||
| CVE-2015-8255 | Hig | 0.60 | 8.8 | 0.02 | Apr 10, 2017 | AXIS Communications products allow CSRF, as demonstrated by admin/pwdgrp.cgi, vaconfig.cgi, and admin/local_del.cgi. | ||
| CVE-2025-30023 | Cri | 0.59 | 9.0 | 0.01 | Jul 11, 2025 | The communication protocol used between client and server had a flaw that could lead to an authenticated user performing a remote code execution attack. | ||
| CVE-2023-21413 | Cri | 0.59 | 9.1 | 0.01 | Oct 16, 2023 | GoSecure on behalf of Genetec Inc. has found a flaw that allows for a remote code execution during the installation of ACAP applications on the Axis device. The application handling service in AXIS OS was vulnerable to command injection allowing an attacker to run arbitrary… | ||
| CVE-2025-0358 | Hig | 0.57 | 8.8 | 0.00 | Jun 2, 2025 | During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework that allowed a privilege escalation, enabling a lower-privileged user to gain administrator privileges. | ||
| CVE-2023-21407 | Hig | 0.57 | 8.8 | 0.01 | Aug 3, 2023 | A broken access control was found allowing for privileged escalation of the operator account to gain administrator privileges. | ||
| CVE-2021-31988 | Hig | 0.57 | 8.8 | 0.01 | Oct 5, 2021 | A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to add the Carriage Return and Line Feed (CRLF) control characters and include arbitrary SMTP headers in the generated test email. | ||
| CVE-2025-10714 | Hig | 0.55 | 8.4 | 0.00 | Nov 11, 2025 | AXIS Optimizer was vulnerable to an unquoted search path vulnerability, which could potentially lead to privilege escalation within Microsoft Windows operating system. This vulnerability can only be exploited if the attacker has access to the local Windows machine and sufficient… | ||
| CVE-2025-0359 | Hig | 0.55 | 8.5 | 0.00 | Mar 4, 2025 | During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the ACAP Application framework that allowed applications to access restricted D-Bus methods within the framework. Axis has released patched AXIS OS versions for the… | ||
| CVE-2023-21409 | Hig | 0.55 | 8.4 | 0.01 | Aug 3, 2023 | Due to insufficient file permissions, unprivileged users could gain access to unencrypted administrator credentials allowing the configuration of the application. | ||
| CVE-2023-21408 | Hig | 0.55 | 8.4 | 0.01 | Aug 3, 2023 | Due to insufficient file permissions, unprivileged users could gain access to unencrypted user credentials that are used in the integration interface towards 3rd party systems. | ||
| CVE-2015-8258 | Hig | 0.52 | 7.5 | 0.09 | Apr 10, 2017 | AXIS Communications products with firmware through 5.80.x allow remote attackers to modify arbitrary files as root via vectors involving Open Script Editor, aka a "resource injection vulnerability." | ||
| CVE-2025-11547 | Hig | 0.51 | 7.8 | 0.00 | Feb 10, 2026 | AXIS Camera Station Pro contained a flaw to perform a privilege escalation attack on the server as a non-admin user. | ||
| CVE-2025-30025 | Hig | 0.51 | 7.8 | 0.00 | Jul 11, 2025 | The communication protocol used between the server process and the service control had a flaw that could lead to a local privilege escalation. |
- risk 0.74cvss 9.8epss 0.87
An issue was discovered in multiple models of Axis IP Cameras. There is a bypass of access control.
- risk 0.73cvss 9.8epss 0.80
An issue was discovered in multiple models of Axis IP Cameras. There is an Exposed Insecure Interface.
- risk 0.73cvss 9.8epss 0.82
An issue was discovered in multiple models of Axis IP Cameras. There is Shell Command Injection.
- risk 0.64cvss 9.8epss 0.01
The AXIS Camera Station Server had a flaw that allowed to bypass authentication that is normally required.
- risk 0.64cvss 9.8epss 0.02
A vulnerability, was found in legacy Axis devices such as P3225 and M3005. This affects an unknown part of the component CGI Script. The manipulation leads to improper privilege management. It is possible to initiate the attack remotely.
- risk 0.62cvss 8.8epss 0.18
The devtools.sh script in AXIS network cameras allows remote authenticated users to execute arbitrary commands via shell metacharacters in the app parameter to (1) app_license.shtml, (2) app_license_custom.shtml, (3) app_index.shtml, or (4) app_params.shtml.
- risk 0.61cvss 9.4epss 0.00
The VAPIX Device Configuration framework allowed a privilege escalation, enabling a lower-privileged user to gain administrator privileges.
- risk 0.60cvss 8.8epss 0.02
AXIS Communications products allow CSRF, as demonstrated by admin/pwdgrp.cgi, vaconfig.cgi, and admin/local_del.cgi.
- risk 0.59cvss 9.0epss 0.01
The communication protocol used between client and server had a flaw that could lead to an authenticated user performing a remote code execution attack.
- risk 0.59cvss 9.1epss 0.01
GoSecure on behalf of Genetec Inc. has found a flaw that allows for a remote code execution during the installation of ACAP applications on the Axis device. The application handling service in AXIS OS was vulnerable to command injection allowing an attacker to run arbitrary…
- risk 0.57cvss 8.8epss 0.00
During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework that allowed a privilege escalation, enabling a lower-privileged user to gain administrator privileges.
- risk 0.57cvss 8.8epss 0.01
A broken access control was found allowing for privileged escalation of the operator account to gain administrator privileges.
- risk 0.57cvss 8.8epss 0.01
A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to add the Carriage Return and Line Feed (CRLF) control characters and include arbitrary SMTP headers in the generated test email.
- risk 0.55cvss 8.4epss 0.00
AXIS Optimizer was vulnerable to an unquoted search path vulnerability, which could potentially lead to privilege escalation within Microsoft Windows operating system. This vulnerability can only be exploited if the attacker has access to the local Windows machine and sufficient…
- risk 0.55cvss 8.5epss 0.00
During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the ACAP Application framework that allowed applications to access restricted D-Bus methods within the framework. Axis has released patched AXIS OS versions for the…
- risk 0.55cvss 8.4epss 0.01
Due to insufficient file permissions, unprivileged users could gain access to unencrypted administrator credentials allowing the configuration of the application.
- risk 0.55cvss 8.4epss 0.01
Due to insufficient file permissions, unprivileged users could gain access to unencrypted user credentials that are used in the integration interface towards 3rd party systems.
- risk 0.52cvss 7.5epss 0.09
AXIS Communications products with firmware through 5.80.x allow remote attackers to modify arbitrary files as root via vectors involving Open Script Editor, aka a "resource injection vulnerability."
- risk 0.51cvss 7.8epss 0.00
AXIS Camera Station Pro contained a flaw to perform a privilege escalation attack on the server as a non-admin user.
- risk 0.51cvss 7.8epss 0.00
The communication protocol used between the server process and the service control had a flaw that could lead to a local privilege escalation.