Description
Erik de Jong, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API ftptest.cgi did not have a sufficient input validation allowing for a possible command injection leading to being able to transfer files from/to the Axis device. This flaw can only be exploited after authenticating with an administrator-privileged service account. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.
References (1)
Core 1
Core References
Scores
CVSS v3
3.8
EPSS
0.0060
EPSS Percentile
43.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-1286
Status
published
Products (3)
axis/axis_os
10.9.0 - 12.1.21
axis/axis_os_2022
< 10.12.257
axis/axis_os_2024
< 11.11.116
Published
Nov 26, 2024
Tracked Since
Feb 18, 2026