Axis Os
Vendor:
First CVE: Oct 5, 2021 · Active for 4 years
36
Total CVEs
More Total CVEs than 97% of tracked products
7.2
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 40% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Axis Os over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 5, 2021
4 years ago
Most Recent CVE
May 12, 2026
73 days ago
CVE Severity & Scoring
Axis Os36 CVEs
53%
44%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local12 (33.3%)
Network21 (58.3%)
Unknown0 (0.0%)
Physical2 (5.6%)
Adjacent Network1 (2.8%)
Attack Complexity
Low33 (91.7%)
High3 (8.3%)
Unknown0 (0.0%)
User Interaction
None29 (80.6%)
Unknown0 (0.0%)
Required7 (19.4%)
Privileges Required
Low17 (47.2%)
High11 (30.6%)
None8 (22.2%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (36 CVEs).
36 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-1185HIGH A configuration file on the local file system had improper input validation which could allow code execution and potentially lead to privilege escalation. This vulnerability can on | May 12, 2026 | 8.8 | 32 | NO | NO |
CVE-2026-0804HIGH An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to potential privilege escalation. This vulnerability can only be e | May 12, 2026 | 7.3 | 28 | NO | NO |
CVE-2026-0802HIGH An ACAP configuration file lacked sufficient input validation, which could allow command injection and potentially lead to privilege escalation. This vulnerability can only be expl | May 12, 2026 | 7.3 | 28 | NO | NO |
CVE-2026-0541HIGH ACAP applications can gain elevated privileges due to improper input validation during the installation process, potentially leading to privilege escalation. This vulnerability can | May 12, 2026 | 7.3 | 28 | NO | NO |
CVE-2025-11142HIGH The VAPIX API mediaclip.cgi that did not have a sufficient input validation allowing for a possible remote code execution. This flaw can only be exploited after authenticating with | Feb 10, 2026 | 8.8 | 28 | NO | NO |
CVE-2023-5800HIGH Vintage,
member of the AXIS OS Bug Bounty Program, has found that the VAPIX API create_overlay.cgi
did not have a sufficient input validation allowing for a possible remote code
ex | Feb 5, 2024 | 8.8 | 28 | NO | NO |
CVE-2021-31988HIGH A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to add the Carriage Return and Line Feed (CRLF) control characters and | Oct 5, 2021 | 8.8 | 27 | NO | NO |
CVE-2025-0358HIGH During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework that allowed a privilege escalati | Jun 2, 2025 | 8.8 | 25 | NO | NO |
CVE-2025-0324HIGH The VAPIX Device Configuration framework allowed a privilege escalation, enabling a lower-privileged user to gain administrator privileges. | Jun 2, 2025 | 8.8 | 25 | NO | NO |
CVE-2021-31987HIGH A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to bypass blocked network recipients. | Oct 5, 2021 | 7.5 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (36 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (36 CVEs).
Media Mentions
Signals from CVEs in this product scope (36 CVEs).
Top CNAs Publishing CVEs For Axis Os
Top CWEs
Versions
No cataloged versions.