Axis Os

Vendor:

First CVE: Oct 5, 2021 · Active for 4 years

36
Total CVEs
More Total CVEs than 97% of tracked products
7.2
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 40% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Axis Os over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 5, 2021
4 years ago
Most Recent CVE
May 12, 2026
73 days ago

CVE Severity & Scoring

Axis Os36 CVEs
All CVEs352,294 CVEs
LowMediumHigh
Attack Vector
Local12 (33.3%)
Network21 (58.3%)
Unknown0 (0.0%)
Physical2 (5.6%)
Adjacent Network1 (2.8%)
Attack Complexity
Low33 (91.7%)
High3 (8.3%)
Unknown0 (0.0%)
User Interaction
None29 (80.6%)
Unknown0 (0.0%)
Required7 (19.4%)
Privileges Required
Low17 (47.2%)
High11 (30.6%)
None8 (22.2%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (36 CVEs).

36 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A configuration file on the local file system had improper input validation which could allow code execution and potentially lead to privilege escalation. This vulnerability can on
May 12, 20268.832NONO
An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to potential privilege escalation. This vulnerability can only be e
May 12, 20267.328NONO
An ACAP configuration file lacked sufficient input validation, which could allow command injection and potentially lead to privilege escalation. This vulnerability can only be expl
May 12, 20267.328NONO
ACAP applications can gain elevated privileges due to improper input validation during the installation process, potentially leading to privilege escalation. This vulnerability can
May 12, 20267.328NONO
The VAPIX API mediaclip.cgi that did not have a sufficient input validation allowing for a possible remote code execution. This flaw can only be exploited after authenticating with
Feb 10, 20268.828NONO
Vintage, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API create_overlay.cgi did not have a sufficient input validation allowing for a possible remote code ex
Feb 5, 20248.828NONO
A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to add the Carriage Return and Line Feed (CRLF) control characters and
Oct 5, 20218.827NONO
During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework that allowed a privilege escalati
Jun 2, 20258.825NONO
The VAPIX Device Configuration framework allowed a privilege escalation, enabling a lower-privileged user to gain administrator privileges.
Jun 2, 20258.825NONO
A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to bypass blocked network recipients.
Oct 5, 20217.524NONO

Exploit Exposure

Signals from CVEs in this product scope (36 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (36 CVEs).

Media Mentions

Signals from CVEs in this product scope (36 CVEs).

Top CNAs Publishing CVEs For Axis Os

Top CWEs

Versions

No cataloged versions.