CVE-2025-8998: Axis Communications Ab Axis OS

Low severity, CVSS 3.1. EPSS: 0.2% chance of exploitation in the next 30 days.

It was possible to upload files with a specific name to a temporary directory, which may result in process crashes and impact usability. This flaw can only be exploited after authenticating with an operator- or administrator-privileged service account.

Affected products

  • Axis Communications Ab Axis OS: from 6.50.0, before 6.50.5.22 (fixed in 6.50.5.22); from 7.0.0, before 8.40.90 (fixed in 8.40.90); from 9.0.0, before 9.80.124 (fixed in 9.80.124); from 10.0.0, before 10.12.306 (fixed in 10.12.306); from 11.0.0, before 11.11.178 (fixed in 11.11.178); from 12.0.0, before 12.7.27 (fixed in 12.7.27)

Published 2025-11-11. Last modified 2026-06-17.