Executive brief
A security vulnerability exists in Axis network devices that use the AXIS Camera Application Platform (ACAP). If a device is configured to allow unsigned software, an attacker could trick a user into installing a malicious application that grants the attacker higher-level control over the device. This could lead to unauthorized access to video feeds or the disruption of security operations.
Technical details
A command injection vulnerability exists in the AXIS Camera Application Platform (ACAP) configuration file due to improper validation of specified input types (CWE-1287). The flaw allows an attacker to execute arbitrary commands with elevated privileges. Exploitation requires the target device to be configured to allow the installation of unsigned ACAP applications and necessitates that an attacker convinces a user to install a malicious application. The vulnerability affects AXIS OS versions from 12.0.0 up to 12.9.33. Axis has released a vendor advisory and updated firmware to address the issue.
Affected products
- Axis Communications AXIS OS 12.0.0 to 12.9.33
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory: Vendor advisory published by Axis Communications