CVE-2025-0324
- EPSS 0.08%
- Veröffentlicht 02.06.2025 07:32:56
- Zuletzt bearbeitet 15.01.2026 15:42:33
The VAPIX Device Configuration framework allowed a privilege escalation, enabling a lower-privileged user to gain administrator privileges.
CVE-2025-0361
- EPSS 0.2%
- Veröffentlicht 08.04.2025 05:38:02
- Zuletzt bearbeitet 14.01.2026 14:41:02
During an annual penetration test conducted on behalf of Axis Communications, Truesec discovered a flaw in the VAPIX Device Configuration framework that allowed for unauthenticated username enumeration through the VAPIX Device Configuration SSH Manag...
CVE-2024-47261
- EPSS 0.3%
- Veröffentlicht 08.04.2025 05:33:58
- Zuletzt bearbeitet 14.01.2026 14:46:03
51l3nc3, a member of the AXIS OS Bug Bounty Program, has found that the VAPIX API uploadoverlayimage.cgi did not have sufficient input validation to allow an attacker to upload files to block access to create image overlays in the web interface of th...
CVE-2025-0359
- EPSS 0.03%
- Veröffentlicht 04.03.2025 06:15:30
- Zuletzt bearbeitet 22.01.2026 21:01:59
During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the ACAP Application framework that allowed applications to access restricted D-Bus methods within the framework. Axis has released patched AXI...
CVE-2025-0360
- EPSS 0.03%
- Veröffentlicht 04.03.2025 06:15:30
- Zuletzt bearbeitet 22.01.2026 20:59:43
During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework that could lead to an incorrect user privilege level in the VAPIX service account D-Bus API.
CVE-2024-47259
- EPSS 0.21%
- Veröffentlicht 04.03.2025 06:15:29
- Zuletzt bearbeitet 22.01.2026 16:35:55
Girishunawane, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API dynamicoverlay.cgi did not have a sufficient input validation allowing for a possible command injection leading to being able to transfer files to the Axis device w...
CVE-2024-8160
- EPSS 0.05%
- Veröffentlicht 26.11.2024 08:15:07
- Zuletzt bearbeitet 22.01.2026 16:41:04
Erik de Jong, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API ftptest.cgi did not have a sufficient input validation allowing for a possible command injection leading to being able to transfer files from/to the Axis device. Thi...
CVE-2024-6979
- EPSS 0.2%
- Veröffentlicht 10.09.2024 06:15:01
- Zuletzt bearbeitet 14.01.2026 16:10:38
Amin Aliakbari, member of the AXIS OS Bug Bounty Program, has found a broken access control which would lead to less-privileged operator- and/or viewer accounts having more privileges than designed. The risk of exploitation is very low as it requires...