Executive brief
A vulnerability in Axis network devices, such as security cameras and encoders, could allow an authorized user to gain higher-level system permissions. By modifying a specific configuration file, an attacker who already has SSH access to the device can execute unauthorized code. This could lead to a full takeover of the device, potentially compromising the security of the video surveillance network.
Technical details
An improper input validation vulnerability exists in a local configuration file within AXIS OS. The flaw, classified under CWE-732 (Incorrect Permission Assignment for Critical Resource), allows an attacker with existing SSH access and low-level privileges to modify system configurations to execute arbitrary code. This can result in local privilege escalation to a higher-privileged user or root. The attack vector is listed as network-based because SSH is the primary entry point, though it requires valid credentials (PR:L). Axis has addressed this in AXIS OS versions 12.10.37 and later.
Affected products
- Axis Communications AXIS OS 12.0.0 to 12.10.37
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory
- 2026-05-19: other: NVD analysis updated