CVE-2023-5677: Axis m3024-Lve Firmware

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Brandon Rothel from QED Secure Solutions and Sam Hanson of Dragos have found that the VAPIX API tcptest.cgi did not have a sufficient input validation allowing for a possible remote code execution. This flaw can only be exploited after authenticating with an operator- or administrator-privileged service account. The impact of exploiting this vulnerability is lower with operator-privileges compared to administrator-privileges service accounts. Please refer to the Axis security advisory for more information and solution.

Affected products

  • Axis m3024-Lve Firmware: before 5.51.7.7 (fixed in 5.51.7.7)
  • Axis m3025-Ve Firmware: before 5.51.7.7 (fixed in 5.51.7.7)
  • Axis m7014 Firmware: before 5.51.7.7 (fixed in 5.51.7.7)
  • Axis m7016 Firmware: before 5.51.7.7 (fixed in 5.51.7.7)
  • Axis p1214-E Firmware: before 5.51.7.7 (fixed in 5.51.7.7)
  • Axis p7214 Firmware: before 5.51.7.7 (fixed in 5.51.7.7)
  • Axis p7216 Firmware: before 5.51.7.7 (fixed in 5.51.7.7)
  • Axis q7401 Firmware: before 5.51.7.7 (fixed in 5.51.7.7)
  • Axis q7404 Firmware: before 5.51.7.7 (fixed in 5.51.7.7)
  • Axis q7414 Firmware: before 5.51.7.7 (fixed in 5.51.7.7)
  • Axis q7424-R Mk Ii Firmware: before 5.51.3.9 (fixed in 5.51.3.9)

Published 2024-02-05. Last modified 2026-06-17.