📦 Axis Os

by Axis

🔍 What is Axis Os?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-0324

CRITICAL CVSS 9.4 Jun 2, 2025

CVE-2025-0324 is a privilege escalation vulnerability in Axis VAPIX Device Configuration framework that allows authenticated low-privileged users to gain administrator privileges. This affects Axis ne...

CVE-2025-11142

HIGH CVSS 7.1 Feb 10, 2026

CVE-2025-11142 is an OS command injection vulnerability in Axis camera VAPIX API's mediaclip.cgi endpoint that allows authenticated attackers with operator or administrator privileges to execute arbit...

CVE-2025-0358

HIGH CVSS 8.8 Jun 2, 2025

This vulnerability in Axis Communications' VAPIX Device Configuration framework allows lower-privileged users to escalate their privileges to administrator level. It affects Axis network video product...

CVE-2025-0359

HIGH CVSS 8.5 Mar 4, 2025

This vulnerability in Axis Communication's ACAP Application framework allows applications to bypass D-Bus method restrictions, potentially enabling unauthorized access to sensitive system functions. I...

CVE-2023-5553

HIGH CVSS 7.6 Nov 21, 2023

This vulnerability allows attackers to bypass Secure Boot protection on AXIS OS devices, potentially enabling unauthorized firmware modifications or persistent compromise. It affects Axis network came...

CVE-2023-21417

HIGH CVSS 7.1 Nov 21, 2023

This CVE describes a path traversal vulnerability in Axis camera systems' VAPIX API manageoverlayimage.cgi endpoint that allows authenticated users with operator or administrator privileges to delete ...

CVE-2023-21414

HIGH CVSS 7.1 Oct 16, 2023

This vulnerability allows attackers to bypass Secure Boot protection on Axis devices, potentially enabling unauthorized firmware modifications or persistent compromise. It affects Axis devices running...

CVE-2021-31987

HIGH CVSS 7.5 Oct 5, 2021

CVE-2021-31987 is an input validation vulnerability in Axis Communications products that allows attackers to bypass blocked SMTP recipients. This affects network devices with SMTP test functionality e...

CVE-2025-8108

MEDIUM CVSS 6.7 Nov 11, 2025

This CVE describes a privilege escalation vulnerability in Axis devices where improper permissions and lack of input validation in ACAP configuration files could allow attackers to gain elevated privi...

CVE-2025-5718

MEDIUM CVSS 6.8 Nov 11, 2025

This CVE describes a privilege escalation vulnerability in the ACAP Application framework through symlink attacks. It affects Axis devices configured to allow unsigned ACAP application installation. A...

CVE-2025-6298

MEDIUM CVSS 6.7 Nov 11, 2025

This CVE describes a privilege escalation vulnerability in Axis ACAP applications where improper input validation allows malicious applications to gain elevated privileges. It affects Axis devices con...

CVE-2025-6779

MEDIUM CVSS 6.7 Nov 11, 2025

CVE-2025-6779 is an improper permissions vulnerability in ACAP configuration files on Axis devices that could allow command injection and privilege escalation. This affects Axis devices configured to ...

CVE-2025-5454

MEDIUM CVSS 6.4 Nov 11, 2025

This CVE describes a path traversal vulnerability in Axis ACAP configuration files that could allow privilege escalation. It affects Axis devices configured to allow unsigned ACAP application installa...

CVE-2025-5452

MEDIUM CVSS 6.6 Nov 11, 2025

This vulnerability allows malicious ACAP applications to steal admin-level service account credentials from legitimate ACAP applications on Axis devices, potentially enabling privilege escalation. It ...

CVE-2025-3892

MEDIUM CVSS 6.7 Aug 12, 2025

CVE-2025-3892 is a privilege escalation vulnerability in Axis devices that allows ACAP applications to execute with elevated privileges. This affects Axis device users who have enabled installation of...

CVE-2025-30027

MEDIUM CVSS 6.7 Aug 12, 2025

This CVE describes an ACAP configuration file vulnerability in Axis devices that lacks sufficient input validation, potentially allowing arbitrary code execution. The vulnerability requires the device...

CVE-2024-47261

MEDIUM CVSS 4.3 Apr 8, 2025

This vulnerability allows attackers to upload files via the VAPIX API uploadoverlayimage.cgi endpoint in Axis devices, potentially blocking access to create image overlays in the web interface. Attack...