VYPR

Vendor CVEs

Axis

All CVEs

122 total · sorted by risk
  • CVE-2025-3892MedAug 12, 2025
    risk 0.44cvss 6.7epss 0.00

    ACAP applications can be executed with elevated privileges, potentially leading to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to…

  • CVE-2025-30027MedAug 12, 2025
    risk 0.44cvss 6.7epss 0.00

    An ACAP configuration file lacked sufficient input validation, which could allow for arbitrary code execution. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the…

  • CVE-2025-30024MedJul 11, 2025
    risk 0.44cvss 6.8epss 0.00

    The communication protocol used between client and server had a flaw that could be leveraged to execute a man in the middle attack.

  • CVE-2024-6979MedSep 10, 2024
    risk 0.44cvss 6.8epss 0.00

    Amin Aliakbari, member of the AXIS OS Bug Bounty Program, has found a broken access control which would lead to less-privileged operator- and/or viewer accounts having more privileges than designed. The risk of exploitation is very low as it requires complex steps to execute,…

  • CVE-2021-31986MedOct 5, 2021
    risk 0.44cvss 6.8epss 0.01

    User controlled parameters related to SMTP notifications are not correctly validated. This can lead to a buffer overflow resulting in crashes and data leakage.

  • CVE-2025-5452MedNov 11, 2025
    risk 0.43cvss 6.6epss 0.00

    A malicious ACAP application can gain access to admin-level service account credentials used by legitimate ACAP applications, leading to potential privilege escalation of the malicious ACAP application. This vulnerability can only be exploited if the Axis device is configured to…

  • CVE-2025-9055MedNov 11, 2025
    risk 0.42cvss 6.4epss 0.00

    The VAPIX Edge storage API that allowed a privilege escalation, enabling a VAPIX administrator-privileged user to gain Linux Root privileges. This flaw can only be exploited after authenticating with an administrator-privileged service account.

  • CVE-2025-5454MedNov 11, 2025
    risk 0.42cvss 6.4epss 0.00

    An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to potential privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications,…

  • CVE-2024-47260MedMar 4, 2025
    risk 0.42cvss 6.5epss 0.00

    51l3nc3, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API mediaclip.cgi did not have a sufficient input validation allowing for uploading more audio clips then designed resulting in the Axis device running out of memory.  Axis has released patched AXIS OS…

  • CVE-2024-6509MedSep 10, 2024
    risk 0.42cvss 6.5epss 0.00

    Marinus Pfund, member of the AXIS OS Bug Bounty Program, has found the VAPIX API alwaysmulti.cgi was vulnerable for file globbing which could lead to resource exhaustion of the Axis device. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to…

  • CVE-2024-6173MedSep 10, 2024
    risk 0.42cvss 6.5epss 0.00

    51l3nc3, member of the AXIS OS Bug Bounty Program, has found that a Guard Tour VAPIX API parameter allowed the use of arbitrary values allowing for an attacker to block access to the guard tour configuration page in the web interface of the Axis device. Axis has released…

  • CVE-2024-0055MedMar 19, 2024
    risk 0.42cvss 6.5epss 0.01

    Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX APIs mediaclip.cgi and playclip.cgi was vulnerable for file globbing which could lead to a resource exhaustion attack. Axis has released patched AXIS OS versions for the highlighted flaw. Please…

  • CVE-2024-0054MedMar 19, 2024
    risk 0.42cvss 6.5epss 0.01

    Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX APIs local_list.cgi, create_overlay.cgi and irissetup.cgi was vulnerable for file globbing which could lead to a resource exhaustion attack. Axis has released patched AXIS OS versions for the…

  • CVE-2023-21415MedOct 16, 2023
    risk 0.42cvss 6.5epss 0.01

    Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API overlay_del.cgi is vulnerable to path traversal attacks that allows for file deletion. This flaw can only be exploited after authenticating with an operator- or administrator-privileged service…

  • CVE-2023-21405MedJul 25, 2023
    risk 0.42cvss 6.5epss 0.00

    Knud from Fraktal.fi has found a flaw in some Axis Network Door Controllers and Axis Network Intercoms when communicating over OSDP, highlighting that the OSDP message parser crashes the pacsiod process, causing a temporary unavailability of the door-controlling functionalities…

  • CVE-2024-7696MedJan 7, 2025
    risk 0.41cvss 6.3epss 0.00

    Seth Fogie, member of AXIS Camera Station Pro Bug Bounty Program, has found that it is possible for an authenticated malicious client to tamper with audit log creation in AXIS Camera Station, or perform a Denial-of-Service attack on the AXIS Camera Station server using…

  • CVE-2024-6749MedNov 26, 2024
    risk 0.41cvss 6.3epss 0.00

    Seth Fogie, member of the AXIS Camera Station Pro Bug Bounty Program, has found that the Incident report feature may expose sensitive credentials on the AXIS Camera Station windows client. If Incident report is not being used with credentials configured this flaw does not apply.…

  • CVE-2023-5677MedFeb 5, 2024
    risk 0.41cvss 6.3epss 0.01

    Brandon Rothel from QED Secure Solutions and Sam Hanson of Dragos have found that the VAPIX API tcptest.cgi did not have a sufficient input validation allowing for a possible remote code execution. This flaw can only be exploited after authenticating with an operator- or…

  • CVE-2025-1056MedApr 23, 2025
    risk 0.40cvss 6.1epss 0.00

    Gee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has identified an issue with a specific file that the server is using. A non-admin user can modify this file to either create files or change the content of files in an admin-protected location. Axis has released…

  • CVE-2024-7784MedSep 10, 2024
    risk 0.40cvss 6.1epss 0.00

    During internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device tampering (commonly known as Secure Boot) in AXIS OS making it vulnerable to a sophisticated attack to bypass this protection. To Axis' knowledge, there are no…

  • CVE-2023-22984MedFeb 21, 2023
    risk 0.40cvss 6.1epss 0.00

    A Vulnerability was discovered in Axis 207W network camera. There is a reflected XSS vulnerability in the web administration portal, which allows an attacker to execute arbitrary JavaScript via URL.

  • CVE-2017-15885MedOct 25, 2017
    risk 0.40cvss 6.1epss 0.01

    Reflected XSS in the web administration portal on the Axis 2100 Network Camera 2.03 allows an attacker to execute arbitrary JavaScript via the conf_Layout_OwnTitle parameter to view/view.shtml. NOTE: this might overlap CVE-2007-5214.

  • CVE-2017-12413MedAug 4, 2017
    risk 0.40cvss 6.1epss 0.01

    AXIS 2100 devices 2.43 have XSS via the URI, possibly related to admin/admin.shtml.

  • CVE-2026-0802MedMay 12, 2026
    risk 0.39cvss 6.0epss 0.00

    An ACAP configuration file lacked sufficient input validation, which could allow command injection and potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and…

  • CVE-2026-6181MedAug 11, 2026
    risk 0.38cvss 5.9epss 0.00

    The Device Configuration Framework is vulnerable to an authentication bypass flaw. This flaw can only be exploited after authenticating with a viewer-privileged service account.

  • CVE-2025-0926MedApr 23, 2025
    risk 0.38cvss 5.9epss 0.00

    Gee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has found that it is possible for a non-admin user to remove system files causing a boot loop by redirecting a file deletion when recording video. Axis has released a patched version for the highlighted flaw.…

  • CVE-2026-5304MedAug 11, 2026
    risk 0.37cvss 5.7epss 0.00

    An ACAP configuration file lacks input validation, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to…

  • CVE-2026-5303MedAug 11, 2026
    risk 0.37cvss 5.7epss 0.00

    The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an…

  • CVE-2025-12063MedFeb 10, 2026
    risk 0.37cvss 5.7epss 0.00

    An insecure direct object reference allowed a non-admin user to modify or remove certain data objects without having the appropriate permissions.

  • CVE-2025-7622MedAug 12, 2025
    risk 0.37cvss 5.7epss 0.00

    During an internal security assessment, a Server-Side Request Forgery (SSRF) vulnerability that allowed an authenticated attacker to access internal resources on the server was discovered.

  • CVE-2026-1185MedMay 12, 2026
    risk 0.35cvss 5.4epss 0.00

    A configuration file on the local file system had improper input validation which could allow code execution and potentially lead to privilege escalation. This vulnerability can only be exploited if an attacker can log in to the Axis device using SSH.

  • CVE-2023-5800MedFeb 5, 2024
    risk 0.35cvss 5.4epss 0.01

    Vintage, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API create_overlay.cgi did not have a sufficient input validation allowing for a possible remote code execution. This flaw can only be exploited after authenticating with an operator- or…

  • CVE-2026-8158MedAug 11, 2026
    risk 0.34cvss 5.3epss 0.00

    The Signed Video Framework contained a  buffer overflow issue which could lead the application using this framework to crash. The issue exclusively affects the tools used for the validation of signed content. The AXIS OS device's signed video functionality remains unaffected.

  • CVE-2024-47262MedMar 4, 2025
    risk 0.34cvss 5.3epss 0.00

    Dzmitry Lukyanenka, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API param.cgi was vulnerable to a race condition attack allowing for an attacker to block access to the web interface of the Axis device. Other API endpoints or services not making use of…

  • CVE-2024-0066MedJun 18, 2024
    risk 0.34cvss 5.3epss 0.00

    Johan Fagerström, member of the AXIS OS Bug Bounty Program, has found that a O3C feature may expose sensitive traffic between the client (Axis device) and (O3C) server. If O3C is not being used this flaw does not apply. Axis has released patched AXIS OS versions for the…

  • CVE-2023-21404MedMay 8, 2023
    risk 0.34cvss 5.3epss 0.00

    AXIS OS 11.0.X - 11.3.x use a static RSA key in legacy LUA-components to protect Axis-specific source code. The static RSA key is not used in any other secure communication nor can it be used to compromise the device or any customer data.

  • CVE-2021-31989MedAug 25, 2021
    risk 0.34cvss 5.3epss 0.00

    A user with permission to log on to the machine hosting the AXIS Device Manager client could under certain conditions extract a memory dump from the built-in Windows Task Manager application. The memory dump may potentially contain credentials of connected Axis devices.

  • CVE-2026-6505MedAug 11, 2026
    risk 0.33cvss 5.1epss 0.00

    The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an…

  • CVE-2025-12757MedFeb 10, 2026
    risk 0.30cvss 4.6epss 0.00

    An AXIS Camera Station Pro feature can be exploited in a way that allows a non-admin user to view information they are not permitted to.

  • CVE-2025-13064MedFeb 10, 2026
    risk 0.29cvss 4.5epss 0.00

    A server-side injection was possible for a malicious admin to manipulate the application to include a malicious script which is executed by the server. This attack is only possible if the admin uses a client that have been tampered with.

  • CVE-2024-6831MedNov 26, 2024
    risk 0.29cvss 4.4epss 0.00

    Seth Fogie, member of AXIS Camera Station Pro Bug Bounty Program has found that it is possible to edit and/or remove views without the necessary permission due to a client-side-only check. Axis has released patched versions for the highlighted flaw. Please refer to the Axis…

  • CVE-2025-9524MedNov 11, 2025
    risk 0.28cvss 4.3epss 0.00

    The VAPIX API port.cgi did not have sufficient input validation, which may result in process crashes and impact usability. This vulnerability can only be exploited after authenticating with a viewer- operator- or administrator-privileged service account.

  • CVE-2025-0325MedJun 2, 2025
    risk 0.28cvss 4.3epss 0.00

    A Guard Tour VAPIX API parameter allowed the use of arbitrary values and can be incorrectly called, allowing an attacker to block access to the guard tour configuration page in the web interface of the Axis device.

  • CVE-2025-0361MedApr 8, 2025
    risk 0.28cvss 4.3epss 0.00

    During an annual penetration test conducted on behalf of Axis Communications, Truesec discovered a flaw in the VAPIX Device Configuration framework that allowed for unauthenticated username enumeration through the VAPIX Device Configuration SSH Management API.

  • CVE-2024-47261MedApr 8, 2025
    risk 0.28cvss 4.3epss 0.00

    51l3nc3, a member of the AXIS OS Bug Bounty Program, has found that the VAPIX API uploadoverlayimage.cgi did not have sufficient input validation to allow an attacker to upload files to block access to create image overlays in the web interface of the Axis device.

  • CVE-2024-8772MedNov 26, 2024
    risk 0.28cvss 4.3epss 0.00

    51l3nc3, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API managedoverlayimages.cgi was vulnerable to a race condition attack allowing for an attacker to block access to the overlay configuration page in the web interface of the Axis device. This flaw can…

  • CVE-2024-0067MedSep 10, 2024
    risk 0.28cvss 4.3epss 0.00

    Marinus Pfund, member of the AXIS OS Bug Bounty Program, has found the VAPIX API ledlimit.cgi was vulnerable for path traversal attacks allowing to list folder/file names on the local file system of the Axis device. Axis has released patched AXIS OS versions for the…

  • CVE-2024-6476MedNov 26, 2024
    risk 0.27cvss 4.2epss 0.00

    Gee-netics, member of the AXIS Camera Station Pro Bug Bounty Program has found that it is possible for a non-admin user to gain system privileges by redirecting a file deletion upon service restart. Axis has released patched versions for the highlighted flaw. Please refer to…

  • CVE-2024-8160LowNov 26, 2024
    risk 0.25cvss 3.8epss 0.01

    Erik de Jong, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API ftptest.cgi did not have a sufficient input validation allowing for a possible command injection leading to being able to transfer files from/to the Axis device. This flaw can only be exploited…

  • CVE-2024-47259LowMar 4, 2025
    risk 0.23cvss 3.5epss 0.01

    Girishunawane, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API dynamicoverlay.cgi did not have a sufficient input validation allowing for a possible command injection leading to being able to transfer files to the Axis device with the purpose to exhaust…