Executive brief
Axis network cameras and video management devices expose a code execution vulnerability in their VAPIX API, a set of interfaces used to configure and control camera functionality. An attacker with administrator credentials can supply malicious input to an API parameter to execute arbitrary code and potentially escalate privileges on the affected device.
Technical details
The VAPIX API parameter validation flaw is a code injection vulnerability stemming from insufficient input sanitization on an unspecified API endpoint. Exploitation requires valid authentication with administrator-level privileges, meaning an attacker must first obtain or compromise an administrator service account. Once authenticated, the attacker can submit a specially crafted parameter value to achieve arbitrary code execution, potentially leading to privilege escalation or further system compromise. The vulnerability has not been observed in active exploitation in the wild. Patches are expected from Axis through their normal security update process.
Affected products
- Axis VAPIX API
Timeline
- 2026-08-11: disclosed