CVE-2025-11142

7.1

Axis Communications · AXIS OS

A command injection vulnerability in the VAPIX API mediaclip.cgi component allows authenticated users with operator or administrator privileges to achieve remote code execution.

Executive summary

A remote code execution vulnerability in Axis Communications AXIS OS firmware poses a significant risk to network security for organizations utilizing affected surveillance devices.

Vulnerability

This flaw is a result of improper input validation within the mediaclip.cgi interface, which allows for OS command injection. Successful exploitation requires a valid session with operator or administrator privileges.

Business impact

Successful exploitation of this vulnerability permits an authenticated attacker to execute arbitrary OS commands on the target device. Given the CVSS score of 7.1, this is a high severity issue that could lead to full device compromise, unauthorized surveillance, or the integration of the device into a botnet. Such a breach results in significant operational downtime and potential compromise of sensitive physical security infrastructure.

Remediation

Immediate Action: Update all affected Axis devices to a firmware version outside the vulnerable range of 12.6.54 through 12.7.35 as specified in the vendor advisory.

Proactive Monitoring: Monitor device access logs for suspicious activity originating from operator or administrator accounts, particularly requests directed toward the mediaclip.cgi endpoint.

Compensating Controls: Restrict network access to the device management interface to trusted administrative subnets and enforce strong, unique credentials to prevent unauthorized account access.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Organizations must prioritize the identification of all Axis Communications devices within their environment and verify their firmware status immediately. Given that this vulnerability allows for command execution, patching is the only effective way to neutralize the risk. Ensure that administrative access is strictly managed and audited to prevent the prerequisite authentication from being met by unauthorized parties.

Sources

Originally found and disclosed by 51l3nc3, per the CVE Program record.