The devtools.sh script in AXIS network cameras allows remote authenticated users to execute arbitrary commands via shell metacharacters in the app parameter to (1) app_license.shtml, (2) app_license_custom.shtml, (3) app_index.shtml, or (4) app_params.shtml.
2017-05-02T14:59:00.177
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 8.8 (HIGH)
AV:N/AC:L/Au:S/C:C/I:C/A:C
8.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | axis | network_camera_firmware | - | Yes |
Hardware | axis | cannon_network_camera | - | No |
Hardware | axis | explosion-protected_camera | - | No |
Hardware | axis | fixed_box_camera | - | No |
Hardware | axis | fixed_bullet_camera | - | No |
Hardware | axis | fixed_dome_camera | - | No |
Hardware | axis | modular_camera | - | No |
Hardware | axis | onboard_camera | - | No |
Hardware | axis | panoramic_camera | - | No |
Hardware | axis | ptz_camera | - | No |
Hardware | axis | thermal_camera | - | No |