First published: Tue May 02 2017(Updated: )
The devtools.sh script in AXIS network cameras allows remote authenticated users to execute arbitrary commands via shell metacharacters in the app parameter to (1) app_license.shtml, (2) app_license_custom.shtml, (3) app_index.shtml, or (4) app_params.shtml.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Axis Network Camera Firmware | ||
Axis Cannon Network Camera | ||
Axis Explosion-protected Camera | ||
Axis Fixed Box Camera | ||
Axis Fixed Bullet Camera | ||
Axis Fixed Dome Camera | ||
Axis Modular Camera | ||
Axis Onboard Camera | ||
Axis Panoramic Camera | ||
Axis Ptz Camera | ||
Axis Thermal Camera |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.