Axis Communications AB manufactures a broad portfolio of network cameras, video management systems, and embedded operating systems that span enterprise surveillance, access control, and IoT deployments across diverse vertical markets. The vendor's vulnerability exposure reflects the complexity of networked embedded devices: a meaningful share of disclosures reach serious severity, and vulnerabilities in this portfolio have frequently acquired public exploit code, consistent with the appeal of internet-accessible camera and management systems for reconnaissance and lateral movement. The recurring weaknesses cluster around web-interface handling—cross-site scripting, path traversal, and OS command injection—alongside parser and input-validation issues endemic to firmware-based products, and recur across the vendor's flagship Axis OS, network camera lines, and Camera Station management platform. Defenders should prioritize internet-exposed instances and maintain close tracking of the vendor's firmware release cycles, particularly for legacy devices with extended operational lifespans; live severity, exploitation, and CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Axis Communications AB over time
Of all the CVEs published by Axis Communications AB as a CNA, 69.8% affect products that Axis Communications AB develops as a vendor.
Of all the CVEs published that affect products developed by Axis Communications AB, 60.0% are self-published by Axis Communications AB as a CNA.
Signals from CVEs in this vendor scope (100 CVEs).
100 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-10661CRITICAL An issue was discovered in multiple models of Axis IP Cameras. There is a bypass of access control. | Jun 26, 2018 | 9.8 | 88 | NO | YES |
CVE-2018-10662CRITICAL An issue was discovered in multiple models of Axis IP Cameras. There is an Exposed Insecure Interface. | Jun 26, 2018 | 9.8 | 86 | NO | YES |
CVE-2018-10660CRITICAL An issue was discovered in multiple models of Axis IP Cameras. There is Shell Command Injection. | Jun 26, 2018 | 9.8 | 84 | NO | YES |
CVE-2015-8256MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Axis network cameras. | Apr 17, 2017 | 6.1 | 52 | NO | YES |
CVE-2003-0240HIGH The web-based administration capability for various Axis Network Camera products allows remote attackers to bypass access restrictions and modify configuration via an HTTP request | Jun 9, 2003 | 10.0 | 51 | NO | YES |
CVE-2015-8257HIGH The devtools.sh script in AXIS network cameras allows remote authenticated users to execute arbitrary commands via shell metacharacters in the app parameter to (1) app_license.shtm | May 2, 2017 | 8.8 | 40 | NO | YES |
CVE-2000-0191HIGH Axis StorPoint CD allows remote attackers to access administrator URLs without authentication via a .. (dot dot) attack. | Feb 29, 2000 | 10.0 | 40 | NO | YES |
CVE-2007-2239HIGH Stack-based buffer overflow in the SaveBMP method in the AXIS Camera Control (aka CamImage) ActiveX control before 2.40.0.0 in AxisCamControl.ocx in AXIS 2100, 2110, 2120, 2130 PTZ | May 7, 2007 | 9.3 | 38 | NO | YES |
CVE-2004-2425HIGH Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to execute arbitrary commands via accent (`) and possibly other shell metacharacter | Dec 31, 2004 | 7.5 | 34 | NO | YES |
CVE-2003-1386MEDIUM AXIS 2400 Video Server 2.00 through 2.33 allows remote attackers to obtain sensitive information via an HTTP request to /support/messages, which displays the server's /var/log/mess | Dec 31, 2003 | 6.4 | 34 | NO | YES |
Signals from CVEs in this vendor scope (100 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Axis Communications AB.
Media articles that mention a CVE ID that affects a product developed by Axis Communications AB — matched by CVE ID, not by vendor name.