Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to execute arbitrary commands via accent (`) and possibly other shell metacharacters in the query string to virtualinput.cgi.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| 2100_network_camera | Axis | 2.12 (including) | 2.12 (including) |
| 2100_network_camera | Axis | 2.30 (including) | 2.30 (including) |
| 2100_network_camera | Axis | 2.31 (including) | 2.31 (including) |
| 2100_network_camera | Axis | 2.32 (including) | 2.32 (including) |
| 2100_network_camera | Axis | 2.33 (including) | 2.33 (including) |
| 2100_network_camera | Axis | 2.34 (including) | 2.34 (including) |
| 2100_network_camera | Axis | 2.40 (including) | 2.40 (including) |
| 2100_network_camera | Axis | 2.41 (including) | 2.41 (including) |
| 2110_network_camera | Axis | 2.12 (including) | 2.12 (including) |
| 2110_network_camera | Axis | 2.30 (including) | 2.30 (including) |
| 2110_network_camera | Axis | 2.31 (including) | 2.31 (including) |
| 2110_network_camera | Axis | 2.32 (including) | 2.32 (including) |
| 2110_network_camera | Axis | 2.34 (including) | 2.34 (including) |
| 2110_network_camera | Axis | 2.40 (including) | 2.40 (including) |
| 2110_network_camera | Axis | 2.41 (including) | 2.41 (including) |
| 2120_network_camera | Axis | 2.12 (including) | 2.12 (including) |
| 2120_network_camera | Axis | 2.30 (including) | 2.30 (including) |
| 2120_network_camera | Axis | 2.31 (including) | 2.31 (including) |
| 2120_network_camera | Axis | 2.32 (including) | 2.32 (including) |
| 2120_network_camera | Axis | 2.34 (including) | 2.34 (including) |
| 2120_network_camera | Axis | 2.40 (including) | 2.40 (including) |
| 2120_network_camera | Axis | 2.41 (including) | 2.41 (including) |
| 2130_ptz_network_camera | Axis | 2.30 (including) | 2.30 (including) |
| 2130_ptz_network_camera | Axis | 2.31 (including) | 2.31 (including) |
| 2130_ptz_network_camera | Axis | 2.32 (including) | 2.32 (including) |
| 2130_ptz_network_camera | Axis | 2.34 (including) | 2.34 (including) |
| 2130_ptz_network_camera | Axis | 2.40 (including) | 2.40 (including) |
| 230_mpeg2_video_server | Axis | 3.11 (including) | 3.11 (including) |
| 2400_video_server | Axis | 1.1 (including) | 1.1 (including) |
| 2400_video_server | Axis | 1.2 (including) | 1.2 (including) |
| 2400_video_server | Axis | 1.10 (including) | 1.10 (including) |
| 2400_video_server | Axis | 1.11 (including) | 1.11 (including) |
| 2400_video_server | Axis | 1.12 (including) | 1.12 (including) |
| 2400_video_server | Axis | 1.15 (including) | 1.15 (including) |
| 2400_video_server | Axis | 2.0 (including) | 2.0 (including) |
| 2400_video_server | Axis | 2.20 (including) | 2.20 (including) |
| 2400_video_server | Axis | 2.30 (including) | 2.30 (including) |
| 2400_video_server | Axis | 2.31 (including) | 2.31 (including) |
| 2400_video_server | Axis | 2.32 (including) | 2.32 (including) |
| 2400_video_server | Axis | 2.33 (including) | 2.33 (including) |
| 2400_video_server | Axis | 2.34 (including) | 2.34 (including) |
| 2400_video_server | Axis | 3.11 (including) | 3.11 (including) |
| 2400_video_server | Axis | 3.12 (including) | 3.12 (including) |
| 2401_video_server | Axis | 1.0_1 (including) | 1.0_1 (including) |
| 2401_video_server | Axis | 1.15 (including) | 1.15 (including) |
| 2401_video_server | Axis | 2.20 (including) | 2.20 (including) |
| 2401_video_server | Axis | 2.30 (including) | 2.30 (including) |
| 2401_video_server | Axis | 2.31 (including) | 2.31 (including) |
| 2401_video_server | Axis | 2.32 (including) | 2.32 (including) |
| 2401_video_server | Axis | 2.33 (including) | 2.33 (including) |
| 2401_video_server | Axis | 2.34 (including) | 2.34 (including) |
| 2401_video_server | Axis | 3.12 (including) | 3.12 (including) |
| 2401_video_server | Axis | 3.13 (including) | 3.13 (including) |
| 2411_video_server | Axis | 3.12 (including) | 3.12 (including) |
| 2411_video_server | Axis | 3.13 (including) | 3.13 (including) |
| 2420_network_camera | Axis | 2.12 (including) | 2.12 (including) |
| 2420_network_camera | Axis | 2.30 (including) | 2.30 (including) |
| 2420_network_camera | Axis | 2.31 (including) | 2.31 (including) |
| 2420_network_camera | Axis | 2.32 (including) | 2.32 (including) |
| 2420_network_camera | Axis | 2.33 (including) | 2.33 (including) |
| 2420_network_camera | Axis | 2.34 (including) | 2.34 (including) |
| 2420_network_camera | Axis | 2.40 (including) | 2.40 (including) |
| 2420_network_camera | Axis | 2.41 (including) | 2.41 (including) |
| 2420_video_server | Axis | 2.32 (including) | 2.32 (including) |
| 2420_video_server | Axis | 2.34 (including) | 2.34 (including) |
| 2460_network_dvr | Axis | * | * |
| 2460_network_dvr | Axis | 3.10 (including) | 3.10 (including) |
| 2460_network_dvr | Axis | 3.11 (including) | 3.11 (including) |
| 2490_serial_server | Axis | * | * |
| 2490_serial_server | Axis | 2.11.3 (including) | 2.11.3 (including) |
| 250s_video_server | Axis | * | * |
| 250s_video_server | Axis | 3.03 (including) | 3.03 (including) |
| 250s_video_server | Axis | 3.10 (including) | 3.10 (including) |
| Storpoint_cd | Axis | * | * |