CVE-2018-10661 EXPLOIT
9.8
CRITICAL · CVSS 3.0 · EPSS 86.5% (pctl 100)
Patch early
A public exploit exists.
Description
An issue was discovered in multiple models of Axis IP Cameras. There is a bypass of access control.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 86.5% — more likely to be exploited than 100% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2018-06-26 |
| Last modified | 2026-06-17 |
Affected (40)
| Vendor | Product |
|---|---|
| axis | a1001 |
| axis | a1001 firmware |
| axis | a8004-v |
| axis | a8004-v firmware |
| axis | a8105-e |
| axis | a8105-e firmware |
| axis | a9161 |
| axis | a9161 firmware |
| axis | a9188 |
| axis | a9188 firmware |
| axis | a9188-v |
| axis | a9188-v firmware |
| axis | c1004-e |
| axis | c1004-e firmware |
| axis | c2005 |
| axis | c2005 firmware |
| axis | c3003-e |
| axis | c3003-e firmware |
| axis | c8033 |
| axis | c8033 firmware |
| axis | companion bullet le |
| axis | companion bullet le firmware |
| axis | companion c360 |
| axis | companion c360 firmware |
| axis | companion cube l |
| axis | companion cube l firmware |
| axis | companion cube lw |
| axis | companion cube lw firmware |
| axis | companion dome v |
| axis | companion dome v firmware |
| axis | companion dome wv |
| axis | companion dome wv firmware |
| axis | companion eye l |
| axis | companion eye l firmware |
| axis | companion eye lve |
| axis | companion eye lve firmware |
| axis | companion recorder 4ch |
| axis | companion recorder 4ch firmware |
| axis | companion recorder 8ch |
| axis | companion recorder 8ch firmware |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Axis Network Camera - .srv to parhand Remote Code Execution (Metasploit) | 2018-07-27 |
References
- https://blog.vdoo.com/2018/06/18/vdoo-discovers-significant-vulnerabilities-in-axis-cameras/
- https://www.axis.com/files/faq/Advisory_ACV-128401.pdf
- https://www.axis.com/files/sales/ACV-128401_Affected_Product_List.pdf
- https://www.exploit-db.com/exploits/45100/
- https://blog.vdoo.com/2018/06/18/vdoo-discovers-significant-vulnerabilities-in-axis-cameras/
- https://www.axis.com/files/faq/Advisory_ACV-128401.pdf
- https://www.axis.com/files/sales/ACV-128401_Affected_Product_List.pdf
- https://www.exploit-db.com/exploits/45100/
→ the Explorer · watch your stack · NVD