CameraRisk

CVE-2004-2426

Axis Communications

Published
31 December 2004
Last modified
16 June 2026
CVSS
5.0 v2.0
Severity
medium
EPSS
4.2% (90th pct)
CISA KEV
Not listed
NVD status
Modified
Weaknesses
None assigned

AV:N/AC:L/Au:N/C:N/I:P/A:N

Description

Directory traversal vulnerability in Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to bypass authentication via a .. (dot dot) in an HTTP POST request to ServerManager.srv, then use these privileges to conduct other activities, such as modifying files using editcgi.cgi.

Exploitation

Not listed in the CISA Known Exploited Vulnerabilities catalogue as of 2026.09.04. That is an absence of confirmed public exploitation, not evidence that exploitation has not occurred. EPSS models a 4.2% probability of exploitation activity in the next 30 days, placing it in the top decile of all scored CVEs.

Affected products

ProductVendorTypeVersions named
2100 NETWORK CAMERA Axis Communications IP camera 2.0, 2.01, 2.02, 2.03 +13
2110 NETWORK CAMERA Axis Communications IP camera 2.12, 2.30, 2.31, 2.32 +5
2120 NETWORK CAMERA Axis Communications IP camera 2.12, 2.30, 2.31, 2.32 +5
2130 PTZ NETWORK CAMERA Axis Communications IP camera 2.30, 2.31, 2.32, 2.34 +3
230 MPEG2 VIDEO SERVER Axis Communications Video management software 3.11
2400 VIDEO SERVER Axis Communications Video management software 1.1, 1.10, 1.11, 1.12 +13
2401 VIDEO SERVER Axis Communications Video management software 1.0_1, 1.15, 2.20, 2.30 +8
2411 VIDEO SERVER Axis Communications Video management software 3.12, 3.13, <= 2.39
2420 NETWORK CAMERA Axis Communications IP camera 2.12, 2.30, 2.31, 2.32 +6
2420 VIDEO SERVER Axis Communications Video management software 2.32, 2.34
2460 NETWORK DVR Axis Communications Digital video recorder 3.10, 3.11, 3.12, <= 3.00
2490 SERIAL SERVER Axis Communications Video management software 2.11.3
250S VIDEO SERVER Axis Communications Video management software 3.03, 3.10, <= 3.02
Storpoint Cd Axis Communications unknown

References

Vendor advisory and patch

CVE-2004-2426 at NVD

Record assembled from NVD, CISA KEV 2026.09.04 and FIRST EPSS 2026-09-04. Affected products are those NVD's CPE configuration names that fall inside this site's scope; a CVE may affect products outside it.