Home
MEDIUM: 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:LDefault status
unaffected
12.0.0 (semver) before 12.10.36
affected
Description
A configuration file on the local file system had improper input validation which could allow code execution and potentially lead to privilege escalation. This vulnerability can only be exploited if an attacker can log in to the Axis device using SSH.
Problem types
CWE-732: Incorrect Permission Assignment for Critical Resource
Product status
12.0.0 (semver) before 12.10.36
Credits
Cookiejack15
References
www.axis.com/...c/69/df/8d/cve-2026-1185pdf-en-US-530733.pdf