VYPR

Vendor CVEs

Axis

All CVEs

99 total · sorted by risk
  • CVE-2025-3892Aug 12, 2025
    risk 0.00cvss epss 0.00

    ACAP applications can be executed with elevated privileges, potentially leading to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to…

  • CVE-2025-7622Aug 12, 2025
    risk 0.00cvss epss 0.00

    During an internal security assessment, a Server-Side Request Forgery (SSRF) vulnerability that allowed an authenticated attacker to access internal resources on the server was discovered.

  • CVE-2025-30026Jul 11, 2025
    risk 0.00cvss epss 0.01

    The AXIS Camera Station Server had a flaw that allowed to bypass authentication that is normally required.

  • CVE-2025-30025Jul 11, 2025
    risk 0.00cvss epss 0.00

    The communication protocol used between the server process and the service control had a flaw that could lead to a local privilege escalation.

  • CVE-2025-0358Jun 2, 2025
    risk 0.00cvss epss 0.00

    During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework that allowed a privilege escalation, enabling a lower-privileged user to gain administrator privileges.

  • CVE-2025-0926Apr 23, 2025
    risk 0.00cvss epss 0.00

    Gee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has found that it is possible for a non-admin user to remove system files causing a boot loop by redirecting a file deletion when recording video. Axis has released a patched version for the highlighted flaw.…

  • CVE-2025-1056Apr 23, 2025
    risk 0.00cvss epss 0.00

    Gee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has identified an issue with a specific file that the server is using. A non-admin user can modify this file to either create files or change the content of files in an admin-protected location. Axis has released…

  • CVE-2025-0361Apr 8, 2025
    risk 0.00cvss epss 0.00

    During an annual penetration test conducted on behalf of Axis Communications, Truesec discovered a flaw in the VAPIX Device Configuration framework that allowed for unauthenticated username enumeration through the VAPIX Device Configuration SSH Management API.

  • CVE-2024-47261Apr 8, 2025
    risk 0.00cvss epss 0.00

    51l3nc3, a member of the AXIS OS Bug Bounty Program, has found that the VAPIX API uploadoverlayimage.cgi did not have sufficient input validation to allow an attacker to upload files to block access to create image overlays in the web interface of the Axis device.

  • CVE-2025-0360Mar 4, 2025
    risk 0.00cvss epss 0.00

    During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework that could lead to an incorrect user privilege level in the VAPIX service account D-Bus API.

  • CVE-2024-47259Mar 4, 2025
    risk 0.00cvss epss 0.01

    Girishunawane, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API dynamicoverlay.cgi did not have a sufficient input validation allowing for a possible command injection leading to being able to transfer files to the Axis device with the purpose to exhaust…

  • CVE-2024-7696Jan 7, 2025
    risk 0.00cvss epss 0.00

    Seth Fogie, member of AXIS Camera Station Pro Bug Bounty Program, has found that it is possible for an authenticated malicious client to tamper with audit log creation in AXIS Camera Station, or perform a Denial-of-Service attack on the AXIS Camera Station server using…

  • CVE-2024-8160Nov 26, 2024
    risk 0.00cvss epss 0.01

    Erik de Jong, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API ftptest.cgi did not have a sufficient input validation allowing for a possible command injection leading to being able to transfer files from/to the Axis device. This flaw can only be exploited…

  • CVE-2024-6979Sep 10, 2024
    risk 0.00cvss epss 0.00

    Amin Aliakbari, member of the AXIS OS Bug Bounty Program, has found a broken access control which would lead to less-privileged operator- and/or viewer accounts having more privileges than designed. The risk of exploitation is very low as it requires complex steps to execute,…

  • CVE-2024-0055Mar 19, 2024
    risk 0.00cvss epss 0.01

    Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX APIs mediaclip.cgi and playclip.cgi was vulnerable for file globbing which could lead to a resource exhaustion attack. Axis has released patched AXIS OS versions for the highlighted flaw. Please…

  • CVE-2023-5800Feb 5, 2024
    risk 0.00cvss epss 0.01

    Vintage, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API create_overlay.cgi did not have a sufficient input validation allowing for a possible remote code execution. This flaw can only be exploited after authenticating with an operator- or…

  • CVE-2023-5677Feb 5, 2024
    risk 0.00cvss epss 0.01

    Brandon Rothel from QED Secure Solutions and Sam Hanson of Dragos have found that the VAPIX API tcptest.cgi did not have a sufficient input validation allowing for a possible remote code execution. This flaw can only be exploited after authenticating with an operator- or…

  • CVE-2023-5553Nov 21, 2023
    risk 0.00cvss epss 0.00

    During internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device tampering (commonly known as Secure Boot) in AXIS OS making it vulnerable to a sophisticated attack to bypass this protection. To Axis' knowledge, there are no…

  • CVE-2023-21418Nov 21, 2023
    risk 0.00cvss epss 0.01

    Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API irissetup.cgi was vulnerable to path traversal attacks that allows for file deletion. This flaw can only be exploited after authenticating with an operator- or administrator-privileged service…

  • CVE-2023-21417Nov 21, 2023
    risk 0.00cvss epss 0.01

    Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API manageoverlayimage.cgi was vulnerable to path traversal attacks that allows for file/folder deletion. This flaw can only be exploited after authenticating with an operator- or administrator-…

  • CVE-2023-21416Nov 21, 2023
    risk 0.00cvss epss 0.01

    Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API dynamicoverlay.cgi was vulnerable to a Denial-of-Service attack allowing for an attacker to block access to the overlay configuration page in the web interface of the Axis device. This flaw can…

  • CVE-2023-21415Oct 16, 2023
    risk 0.00cvss epss 0.01

    Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API overlay_del.cgi is vulnerable to path traversal attacks that allows for file deletion. This flaw can only be exploited after authenticating with an operator- or administrator-privileged service…

  • CVE-2023-21414Oct 16, 2023
    risk 0.00cvss epss 0.00

    NCC Group has found a flaw during the annual internal penetration test ordered by Axis Communications. The protection for device tampering (commonly known as Secure Boot) contains a flaw which provides an opportunity for a sophisticated attack to bypass this protection. Axis has…

  • CVE-2023-21413Oct 16, 2023
    risk 0.00cvss epss 0.01

    GoSecure on behalf of Genetec Inc. has found a flaw that allows for a remote code execution during the installation of ACAP applications on the Axis device. The application handling service in AXIS OS was vulnerable to command injection allowing an attacker to run arbitrary…

  • CVE-2023-21412Aug 3, 2023
    risk 0.00cvss epss 0.00

    User provided input is not sanitized on the AXIS License Plate Verifier specific “search.cgi” allowing for SQL injections.

  • CVE-2023-21411Aug 3, 2023
    risk 0.00cvss epss 0.01

    User provided input is not sanitized in the “Settings > Access Control” configuration interface allowing for arbitrary code execution.

  • CVE-2023-21410Aug 3, 2023
    risk 0.00cvss epss 0.01

    User provided input is not sanitized on the AXIS License Plate Verifier specific “api.cgi” allowing for arbitrary code execution.

  • CVE-2023-21409Aug 3, 2023
    risk 0.00cvss epss 0.01

    Due to insufficient file permissions, unprivileged users could gain access to unencrypted administrator credentials allowing the configuration of the application.

  • CVE-2023-21408Aug 3, 2023
    risk 0.00cvss epss 0.01

    Due to insufficient file permissions, unprivileged users could gain access to unencrypted user credentials that are used in the integration interface towards 3rd party systems.

  • CVE-2023-21407Aug 3, 2023
    risk 0.00cvss epss 0.01

    A broken access control was found allowing for privileged escalation of the operator account to gain administrator privileges.

  • CVE-2023-21406Jul 25, 2023
    risk 0.00cvss epss 0.00

    Ariel Harush and Roy Hodir from OTORIO have found a flaw in the AXIS A1001 when communicating over OSDP. A heap-based buffer overflow was found in the pacsiod process which is handling the OSDP communication allowing to write outside of the allocated buffer. By appending invalid…

  • CVE-2023-21405Jul 25, 2023
    risk 0.00cvss epss 0.00

    Knud from Fraktal.fi has found a flaw in some Axis Network Door Controllers and Axis Network Intercoms when communicating over OSDP, highlighting that the OSDP message parser crashes the pacsiod process, causing a temporary unavailability of the door-controlling functionalities…

  • CVE-2023-21404May 8, 2023
    risk 0.00cvss epss 0.00

    AXIS OS 11.0.X - 11.3.x use a static RSA key in legacy LUA-components to protect Axis-specific source code. The static RSA key is not used in any other secure communication nor can it be used to compromise the device or any customer data.

  • CVE-2023-22984Feb 21, 2023
    risk 0.00cvss epss 0.00

    A Vulnerability was discovered in Axis 207W network camera. There is a reflected XSS vulnerability in the web administration portal, which allows an attacker to execute arbitrary JavaScript via URL.

  • CVE-2017-20049Jun 15, 2022
    risk 0.00cvss epss 0.01

    A vulnerability, was found in legacy Axis devices such as P3225 and M3005. This affects an unknown part of the component CGI Script. The manipulation leads to improper privilege management. It is possible to initiate the attack remotely.

  • CVE-2022-23410Feb 14, 2022
    risk 0.00cvss epss 0.00

    AXIS IP Utility before 4.18.0 allows for remote code execution and local privilege escalation by the means of DLL hijacking. IPUtility.exe would attempt to load DLLs from its current working directory which could allow for remote code execution if a compromised DLL would be…

  • CVE-2008-5260Jan 26, 2009
    risk 0.00cvss epss 0.06

    Heap-based buffer overflow in the CamImage.CamImage.1 ActiveX control in AxisCamControl.ocx in AXIS Camera Control 2.40.0.0 allows remote attackers to execute arbitrary code via a long image_pan_tilt property value.

  • CVE-2007-5212Oct 4, 2007
    risk 0.00cvss epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in the AXIS 2100 Network Camera 2.02 with firmware before 2.43 allow remote attackers to inject arbitrary web script or HTML via (1) parameters associated with saved settings, as demonstrated by the conf_SMTP_MailServer1…

  • CVE-2007-5213Oct 4, 2007
    risk 0.00cvss epss 0.02

    Multiple cross-site request forgery (CSRF) vulnerabilities in the AXIS 2100 Network Camera 2.02 with firmware 2.43 and earlier allow remote attackers to perform actions as administrators, as demonstrated by (1) an SMTP server change through the conf_SMTP_MailServer1 parameter to…

  • CVE-2007-5214Oct 4, 2007
    risk 0.00cvss epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in the AXIS 2100 Network Camera 2.02 with firmware 2.43 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO to the default URI associated with a directory, as demonstrated by (a) the…

  • CVE-2007-4928Sep 18, 2007
    risk 0.00cvss epss 0.00

    The AXIS 207W camera stores a WEP or WPA key in cleartext in the configuration file, which might allow local users to obtain sensitive information.

  • CVE-2007-4929Sep 18, 2007
    risk 0.00cvss epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in the AXIS 207W camera allow remote attackers to inject arbitrary web script or HTML via the camNo parameter to incl/image_incl.shtml, and other unspecified vectors.

  • CVE-2007-4926Sep 18, 2007
    risk 0.00cvss epss 0.03

    The AXIS 207W camera uses a base64-encoded cleartext username and password for authentication, which allows remote attackers to obtain sensitive information by sniffing the wireless network or by leveraging unspecified other vectors.

  • CVE-2007-4927Sep 18, 2007
    risk 0.00cvss epss 0.02

    axis-cgi/buffer/command.cgi on the AXIS 207W camera allows remote authenticated users to cause a denial of service (reboot) via many requests with unique buffer names in the buffername parameter in a start action.

  • CVE-2004-2427Dec 31, 2004
    risk 0.00cvss epss 0.05

    Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to obtain sensitive information via direct requests to (1) admin/getparam.cgi, (2) admin/systemlog.cgi, (3) admin/serverreport.cgi, and (4) admin/paramlist.cgi, modify system…

  • CVE-2004-2426Dec 31, 2004
    risk 0.00cvss epss 0.04

    Directory traversal vulnerability in Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to bypass authentication via a .. (dot dot) in an HTTP POST request to ServerManager.srv, then use these privileges to conduct other activities,…

  • CVE-2004-0789Dec 31, 2004
    risk 0.00cvss epss 0.03

    Multiple implementations of the DNS protocol, including (1) Poslib 1.0.2-1 and earlier as used by Posadis, (2) Axis Network products before firmware 3.13, and (3) Men & Mice Suite 2.2x before 2.2.3 and 3.5.x before 3.5.2, allow remote attackers to cause a denial of service (CPU…

  • CVE-2001-1543Dec 31, 2001
    risk 0.00cvss epss 0.02

    Axis network camera 2120, 2110, 2100, 200+ and 200 contains a default administration password "pass", which allows remote attackers to gain access to the camera.

  • CVE-2000-0144Feb 7, 2000
    risk 0.00cvss epss 0.02

    Axis 700 Network Scanner does not properly restrict access to administrator URLs, which allows users to bypass the password protection via a .. (dot dot) attack.

Page 2 of 2