Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

AxxonSoft Limited

First CVE: Feb 27, 2018Active for: 8 yearsTotal CVEs: 9

AxxonSoft Limited develops a narrow portfolio of video-management and physical-security software, including its flagship Axxon One and Next platforms, which occupy a specialized role in surveillance and access-control infrastructure. Vulnerabilities affecting the vendor skew toward serious outcomes and frequently acquire public exploit code; the recurring weakness classes—including authentication bypass, path traversal, sensitive-information exposure, and memory-safety flaws—reflect the authentication boundaries and file-access control inherent to a networked security appliance. Defenders managing these platforms should treat disclosed vulnerabilities as urgent; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
2.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by AxxonSoft Limited over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 27, 2018
8 years ago
Most Recent CVE
Sep 10, 2025
317 days ago

Self-Reporting Analysis

Of all the CVEs published by AxxonSoft Limited as a CNA, 100.0% affect products that AxxonSoft Limited develops as a vendor.

100.0%
Self-reported: 8 (100.0%)
Third-party: 0 (0.0%)

Of all the CVEs published that affect products developed by AxxonSoft Limited, 88.9% are self-published by AxxonSoft Limited as a CNA.

88.9%
11.1%
Self-published: 8 (88.9%)
Other CNAs: 1 (11.1%)

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-7467HIGH
AxxonSoft Axxon Next has Directory Traversal via an initial /css//..%2f substring in a URI.
Feb 27, 20187.540NOYES
CVE-2025-10226CRITICAL
Dependency on Vulnerable Third-Party Component (CWE-1395) in the PostgreSQL backend in AxxonSoft Axxon One (C-Werk) 2.0.8 and earlier on Windows and Linux allows a remote attacker
Sep 10, 20259.833NONO
CVE-2025-10220CRITICAL
Use of Unmaintained Third Party Components (CWE-1104) in the NuGet dependency components in AxxonSoft Axxon One VMS 2.0.0 through 2.0.4 on Windows allows a remote attacker to execu
Sep 10, 20259.833NONO
CVE-2025-10225HIGH
Improper Restriction of Operations within the Bounds of a Memory Buffer (CWE-119) in the OpenSSL-based session module in AxxonSoft Axxon One (C-Werk) 2.0.6 and earlier on Windows a
Sep 10, 20257.525NONO
CVE-2025-10223HIGH
Insufficient Session Expiration (CWE-613) in the Web Admin Panel in AxxonSoft Axxon One (C-Werk) prior to 2.0.3 on Windows allows a local or remote authenticated attacker to retain
Sep 10, 20258.125NONO
CVE-2025-10224HIGH
Improper Authentication (CWE-287) in the LDAP authentication engine in AxxonSoft Axxon One (C-Werk) 2.0.2 and earlier on Windows allows a remote authenticated user to be denied acc
Sep 10, 20257.124NONO
CVE-2025-10221MEDIUM
Insertion of Sensitive Information into Log File (CWE-532) in the ARP Agent component in AxxonSoft Axxon One / AxxonNet / C-WerkNet 2.0.4 and earlier on Windows platforms allows a
Sep 10, 20255.520NONO
CVE-2025-10227MEDIUM
Missing Encryption of Sensitive Data (CWE-311) in the Object Archive component in AxxonSoft Axxon One (C-Werk) before 2.0.8 on Windows and Linux allows a local attacker with acces
Sep 10, 20254.619NONO
CVE-2025-10222LOW
Exposure of Sensitive Information to an Unauthorized Actor (CWE-200) in the diagnostic dump component in AxxonSoft Axxon One VMS (C-Werk) 2.0.0 through 2.0.1 on Windows allows a lo
Sep 10, 20253.316NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
11%
22%
44%
22%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (22.2%)
Network6 (66.7%)
Unknown0 (0.0%)
Physical1 (11.1%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low4 (44.4%)
High0 (0.0%)
None5 (55.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
11.1% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by AxxonSoft Limited.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by AxxonSoft Limited — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For AxxonSoft Limited's Products

View all 2 CNAs →

Top CWEs