CVE-2024-47261
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Apr 8, 2025
CWE ID 1287
Summary
CVE-2024-47261 is a newly discovered vulnerability affecting the VAPIX API's uploadoverlayimage.cgi feature in certain Axis devices. The issue stems from insufficient input validation, allowing attackers to upload files and restrict access to create image overlays in the web interface. This vulnerability poses a potential risk, as unauthorized file uploads could lead to unintended system modifications or denial-of-service attacks. Users are strongly encouraged to update their devices to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Axis OS