Vulnerabilities
Vulnerable Software
Axis:  >> Axis Os  >> 12.6.97  Security Vulnerabilities
The VAPIX API mediaclip.cgi that did not have a sufficient input validation allowing for a possible remote code execution. This flaw can only be exploited after authenticating with an operator- or administrator- privileged service account.
CVSS Score
7.1
EPSS Score
0.001
Published
2026-02-10
An ACAP configuration file has improper permissions and lacks input validation, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.
CVSS Score
6.7
EPSS Score
0.0
Published
2025-11-11


Contact Us

Shodan ® - All rights reserved