Axis

Axis Os

54 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.39%
  • Veröffentlicht 11.08.2026 05:52:33
  • Zuletzt bearbeitet 03.09.2026 16:44:01

A VAPIX API parameter had improper input validation which could allow code execution and potentially lead to a privilege escalation. This flaw can only be exploited after authenticating with an administrator-privileged service account.

  • EPSS 0.07%
  • Veröffentlicht 11.08.2026 05:49:51
  • Zuletzt bearbeitet 03.09.2026 16:44:01

The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ...

  • EPSS 0.23%
  • Veröffentlicht 11.08.2026 05:47:49
  • Zuletzt bearbeitet 03.09.2026 16:44:01

An ACAP configuration file lacks input validation, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an atta...

  • EPSS 0.17%
  • Veröffentlicht 11.08.2026 05:45:56
  • Zuletzt bearbeitet 03.09.2026 16:44:01

The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ...

  • EPSS 0.23%
  • Veröffentlicht 12.05.2026 05:49:46
  • Zuletzt bearbeitet 19.05.2026 16:07:33

A configuration file on the local file system had improper input validation which could allow code execution and potentially lead to privilege escalation. This vulnerability can only be exploited if an attacker can log in to the Axis device using SSH...

  • EPSS 0.13%
  • Veröffentlicht 12.05.2026 05:46:45
  • Zuletzt bearbeitet 19.05.2026 16:06:01

An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to potential privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of...

  • EPSS 0.4%
  • Veröffentlicht 12.05.2026 05:44:59
  • Zuletzt bearbeitet 19.05.2026 16:05:03

An ACAP configuration file lacked sufficient input validation, which could allow command injection and potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of un...

  • EPSS 0.1%
  • Veröffentlicht 12.05.2026 05:42:27
  • Zuletzt bearbeitet 19.05.2026 15:40:24

ACAP applications can gain elevated privileges due to improper input validation during the installation process, potentially leading to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the insta...

  • EPSS 0.5%
  • Veröffentlicht 10.02.2026 05:32:19
  • Zuletzt bearbeitet 28.02.2026 00:09:21

The VAPIX API mediaclip.cgi that did not have a sufficient input validation allowing for a possible remote code execution. This flaw can only be exploited after authenticating with an operator- or administrator- privileged service account.

  • EPSS 0.23%
  • Veröffentlicht 11.11.2025 07:28:40
  • Zuletzt bearbeitet 15.04.2026 00:35:42

It was possible to upload files with a specific name to a temporary directory, which may result in process crashes and impact usability. This flaw can only be exploited after authenticating with an operator- or administrator-privileged service accoun...