CVE-2017-20049: Axis m3005 Firmware

Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.

A vulnerability, was found in legacy Axis devices such as P3225 and M3005. This affects an unknown part of the component CGI Script. The manipulation leads to improper privilege management. It is possible to initiate the attack remotely.

Affected products

  • Axis m3005 Firmware: up to and including 5.50.5.7
  • Axis m3007 Firmware: up to and including 6.30.1.1
  • Axis m3045 Firmware: up to and including 6.15.4.1
  • Axis p1204 Firmware: up to and including 5.50.4
  • Axis p3225 Firmware: up to and including 6.30.1
  • Axis p3367 Firmware: up to and including 6.10.1.2

Published 2022-06-15. Last modified 2026-06-17.