Axis VAPIX Edge Storage API Privilege Escalation Vulnerability Allowing Root Access

Vulnerability

A privilege escalation vulnerability has been identified in the VAPIX Edge storage API, affecting AXIS OS versions 12.0.0 through 12.7.30. This vulnerability allows a user with VAPIX administrator privileges to gain root access on the Linux operating system. Exploitation of this flaw requires authentication with an administrator-privileged service account.

Impact

Exploitation of this vulnerability could lead to unauthorized root access on the Linux operating system, allowing for complete control over the device.

Remediation

Axis has released a patch for this vulnerability in AXIS OS Active Track 12.7.31. For devices not included in this track but still under support, patches will be provided according to the planned maintenance and release schedule. Users are advised to update their Axis device software to the latest version available.

Added: Nov 11, 2025, 8:20 AM
Updated: Nov 11, 2025, 8:20 AM

Vulnerability Rating

Custom Algorithm
spread
6.8
impact
7.5
exploitability
4.4
remediation
7.7
relevance
0.9
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.