CVE-2024-47261: Axis OS

Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.

51l3nc3, a member of the AXIS OS Bug Bounty Program, has found that the VAPIX API uploadoverlayimage.cgi did not have sufficient input validation to allow an attacker to upload files to block access to create image overlays in the web interface of the Axis device.

Affected products

  • Axis Axis OS: from 10.12.0, before 12.3.56 (fixed in 12.3.56)
  • Axis Axis OS 2022: before 10.12.276 (fixed in 10.12.276)
  • Axis Axis OS 2024: before 11.11.141 (fixed in 11.11.141)

Published 2025-04-08. Last modified 2026-06-17.