peter bassill · operator
$ cve CVE-2004-2425 JSON

CVE-2004-2425 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 13.5% (pctl 96)

Patch early

A public exploit exists.

Description

Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to execute arbitrary commands via accent (`) and possibly other shell metacharacters in the query string to virtualinput.cgi.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS13.53% — more likely to be exploited than 96% of all CVEs
On CISA KEVno
Public exploityes
Published2004-12-31
Last modified2026-06-16

Affected (14)

VendorProduct
axis2100 network camera
axis2110 network camera
axis2120 network camera
axis2130 ptz network camera
axis230 mpeg2 video server
axis2400 video server
axis2401 video server
axis2411 video server
axis2420 network camera
axis2420 video server
axis2460 network dvr
axis2490 serial server
axis250s video server
axisstorpoint cd

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD