Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Axis Communications AB

First CVE: Feb 7, 2000Active for: 26 yearsTotal CVEs: 100
45.2
VTI Score
High

Axis Communications AB manufactures a broad portfolio of network cameras, video management systems, and embedded operating systems that span enterprise surveillance, access control, and IoT deployments across diverse vertical markets. The vendor's vulnerability exposure reflects the complexity of networked embedded devices: a meaningful share of disclosures reach serious severity, and vulnerabilities in this portfolio have frequently acquired public exploit code, consistent with the appeal of internet-accessible camera and management systems for reconnaissance and lateral movement. The recurring weaknesses cluster around web-interface handling—cross-site scripting, path traversal, and OS command injection—alongside parser and input-validation issues endemic to firmware-based products, and recur across the vendor's flagship Axis OS, network camera lines, and Camera Station management platform. Defenders should prioritize internet-exposed instances and maintain close tracking of the vendor's firmware release cycles, particularly for legacy devices with extended operational lifespans; live severity, exploitation, and CVE counts are shown alongside this summary.

FAUCET AI Generated
100
Total CVEs
More Total CVEs than 99% of tracked vendors
0.0
Avg CVEs / Product / Year
Bottom 1%
7.2
Avg CVSS Score
Higher Avg CVSS Score than 54% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Axis Communications AB over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 7, 2000
26 years ago
Most Recent CVE
May 12, 2026
74 days ago

Self-Reporting Analysis

Of all the CVEs published by Axis Communications AB as a CNA, 69.8% affect products that Axis Communications AB develops as a vendor.

69.8%
30.2%
Self-reported: 60 (69.8%)
Third-party: 26 (30.2%)

Of all the CVEs published that affect products developed by Axis Communications AB, 60.0% are self-published by Axis Communications AB as a CNA.

60.0%
40.0%
Self-published: 60 (60.0%)
Other CNAs: 40 (40.0%)

Products(1,082 total)

Top CVEs

Signals from CVEs in this vendor scope (100 CVEs).

100 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-10661CRITICAL
An issue was discovered in multiple models of Axis IP Cameras. There is a bypass of access control.
Jun 26, 20189.888NOYES
CVE-2018-10662CRITICAL
An issue was discovered in multiple models of Axis IP Cameras. There is an Exposed Insecure Interface.
Jun 26, 20189.886NOYES
CVE-2018-10660CRITICAL
An issue was discovered in multiple models of Axis IP Cameras. There is Shell Command Injection.
Jun 26, 20189.884NOYES
CVE-2015-8256MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Axis network cameras.
Apr 17, 20176.152NOYES
CVE-2003-0240HIGH
The web-based administration capability for various Axis Network Camera products allows remote attackers to bypass access restrictions and modify configuration via an HTTP request
Jun 9, 200310.051NOYES
CVE-2015-8257HIGH
The devtools.sh script in AXIS network cameras allows remote authenticated users to execute arbitrary commands via shell metacharacters in the app parameter to (1) app_license.shtm
May 2, 20178.840NOYES
CVE-2000-0191HIGH
Axis StorPoint CD allows remote attackers to access administrator URLs without authentication via a .. (dot dot) attack.
Feb 29, 200010.040NOYES
CVE-2007-2239HIGH
Stack-based buffer overflow in the SaveBMP method in the AXIS Camera Control (aka CamImage) ActiveX control before 2.40.0.0 in AxisCamControl.ocx in AXIS 2100, 2110, 2120, 2130 PTZ
May 7, 20079.338NOYES
CVE-2004-2425HIGH
Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to execute arbitrary commands via accent (`) and possibly other shell metacharacter
Dec 31, 20047.534NOYES
CVE-2003-1386MEDIUM
AXIS 2400 Video Server 2.00 through 2.33 allows remote attackers to obtain sensitive information via an HTTP request to /support/messages, which displays the server's /var/log/mess
Dec 31, 20036.434NOYES
View all 100 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products100 CVEs
42%
48%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local15 (15.0%)
Network54 (54.0%)
Unknown21 (21.0%)
Physical2 (2.0%)
Adjacent Network8 (8.0%)
Attack Complexity
Low69 (69.0%)
High10 (10.0%)
Unknown21 (21.0%)
User Interaction
None61 (61.0%)
Unknown21 (21.0%)
Required18 (18.0%)
Privileges Required
Low33 (33.0%)
High12 (12.0%)
None34 (34.0%)
Unknown21 (21.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (100 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
3.0% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
15 CVEs
15.0% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Axis Communications AB.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Axis Communications AB — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Axis Communications AB's Products

View all 3 CNAs →

Top CWEs