CVE-2024-8160: Axis OS

Low severity, CVSS 2.7. EPSS: 0.6% chance of exploitation in the next 30 days.

Erik de Jong, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API ftptest.cgi did not have a sufficient input validation allowing for a possible command injection leading to being able to transfer files from/to the Axis device. This flaw can only be exploited after authenticating with an administrator-privileged service account. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.

Affected products

  • Axis Axis OS: from 10.9.0, before 12.1.21 (fixed in 12.1.21)
  • Axis Axis OS 2022: before 10.12.257 (fixed in 10.12.257)
  • Axis Axis OS 2024: before 11.11.116 (fixed in 11.11.116)

Published 2024-11-26. Last modified 2026-06-17.