Skip to main content

Vendor/product archive

axis / axis_os CVEs

Beta · best-effort

36 CVEs tagged to axis / axis_os2 Critical, 11 High, 21 Medium, 2 Low, 0 Unrated.

CVE-2026-1185

Published May 12, 2026

A configuration file on the local file system had improper input validation which could allow code execution and potentially lead to privilege escalation. This vulnerability can o…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-0804

Published May 12, 2026

An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to potential privilege escalation. This vulnerability can only be…

CVSS 6.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-0802

Published May 12, 2026

An ACAP configuration file lacked sufficient input validation, which could allow command injection and potentially lead to privilege escalation. This vulnerability can only be exp…

CVSS 6.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-0541

Published May 12, 2026

ACAP applications can gain elevated privileges due to improper input validation during the installation process, potentially leading to privilege escalation. This vulnerability ca…

CVSS 6.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-11142

Published Feb 10, 2026

The VAPIX API mediaclip.cgi that did not have a sufficient input validation allowing for a possible remote code execution. This flaw can only be exploited after authenticating wit…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-6779

Published Nov 11, 2025

An ACAP configuration file has improper permissions, which could allow command injection and potentially lead to privilege escalation. This vulnerability can only be exploited if…

CVSS 6.7 · Medium

CVE-2025-6298

Published Nov 11, 2025

ACAP applications can gain elevated privileges due to improper input validation, potentially leading to privilege escalation. This vulnerability can only be exploited if the Axis…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-5718

Published Nov 11, 2025

The ACAP Application framework could allow privilege escalation through a symlink attack. This vulnerability can only be exploited if the Axis device is configured to allow the in…

CVSS 6.8 · Medium

CVE-2025-5454

Published Nov 11, 2025

An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to potential privilege escalation. This vulnerability can only be…

CVSS 6.4 · Medium

CVE-2025-5452

Published Nov 11, 2025

A malicious ACAP application can gain access to admin-level service account credentials used by legitimate ACAP applications, leading to potential privilege escalation of the mali…

CVSS 6.6 · Medium

CVE-2025-4645

Published Nov 11, 2025

An ACAP configuration file lacked sufficient input validation, which could allow for arbitrary code execution. This vulnerability can only be exploited if the Axis device is confi…

CVSS 6.7 · Medium

CVE-2025-3892

Published Aug 12, 2025

ACAP applications can be executed with elevated privileges, potentially leading to privilege escalation. This vulnerability can only be exploited if the Axis device is configured…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-30027

Published Aug 12, 2025

An ACAP configuration file lacked sufficient input validation, which could allow for arbitrary code execution. This vulnerability can only be exploited if the Axis device is confi…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-0358

Published Jun 2, 2025

During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework that allowed a privilege escalat…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-0324

Published Jun 2, 2025

The VAPIX Device Configuration framework allowed a privilege escalation, enabling a lower-privileged user to gain administrator privileges.

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-0361

Published Apr 8, 2025

During an annual penetration test conducted on behalf of Axis Communications, Truesec discovered a flaw in the VAPIX Device Configuration framework that allowed for unauthenticate…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-0360

Published Mar 4, 2025

During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework that could lead to an incorrect…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-0359

Published Mar 4, 2025

During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the ACAP Application framework that allowed applications to access restri…

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-47259

Published Mar 4, 2025

Girishunawane, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API dynamicoverlay.cgi did not have a sufficient input validation allowing for a possible command…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-0055

Published Mar 19, 2024

Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX APIs mediaclip.cgi and playclip.cgi was vulnerable for file globbing which could lead to a resourc…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-5553

Published Nov 21, 2023

During internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device tampering (commonly known as Secure Boot) in AXIS OS making…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 36 CVEsPage 1 of 2