AXIS VAPIX API endpoint mediaclip.cgi contains insufficient input validation, which may allow an authenticated attacker to achieve remote code execution. Exploitation is only possible after authenticating using an operator- or administrator-privileged service account.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This is a small standalone Python proof-of-concept repository for CVE-2025-11142, an authenticated CWE-78 OS command injection in the AXIS VAPIX Media Clip endpoint /axis-cgi/mediaclip.cgi. The repository contains a MIT license, a detailed README research writeup, requirements.txt specifying requests>=2.31, and the executable poc.py script. It is not part of Metasploit, Nuclei, or another exploit framework. poc.py uses requests with HTTPDigestAuth to communicate with a caller-specified target over HTTP. It first uploads an embedded minimal WAV file as a benign placeholder clip, then submits action=update requests for clip 0 with shell syntax in the name field. Time-based confirmation compares requests containing sleep 0 and sleep 6, treating a delay exceeding the baseline by four seconds as positive evidence. For a stronger test, it starts an embedded HTTP server on all interfaces and injects curl http://{callback_ip}:{callback_port}/rce_confirmed; an inbound request to that server confirms that the target executed the injected command. It subsequently issues remove and play requests for cleanup/state verification. The documented affected range is AXIS OS 12.6.54 through 12.7.35, fixed in 12.7.36. Exploitation requires valid authenticated VAPIX operator/admin access and produces command execution as a low-privileged, non-root service account. Although the included commands are confirmation-oriented rather than a persistent shell or privilege-escalation payload, the injectable name parameter can carry arbitrary shell commands, making this an operational authenticated remote command-execution verifier.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.