
DEF CON 33 - Turning Camera Surveillance on its Axis - Noam Moshe
Source: YouTube · DEFCONConference · published Sep 2, 2025 · 21:56
A security researcher discovered critical vulnerabilities in Axis camera surveillance systems that could allow attackers to gain complete control over enterprise video networks 5:37.
Key Takeaways:
• Axis cameras are widely used in enterprises, schools, medical facilities, and government agencies running on proprietary Axis OS 2:26
• The researcher discovered a JSON deserialization vulnerability in Axis's remote access protocol that enables remote code execution 10:34
• By analyzing a fallback protocol, they found an anonymous authentication endpoint allowing pre-authentication remote code execution 18:42
• Almost 6,500 vulnerable servers were exposed online, many belonging to critical organizations 19:44
Axis responsibly addressed these security issues after disclosure, highlighting the importance of securing IoT camera systems that protect critical infrastructure 21:24.
Sources:
- 2:26 Description of Axis cameras and their enterprise use
- 5:37 Researcher's goal to take control of Axis camera systems
- 10:34 Discovery of JSON deserialization vulnerability
- 13:01 Ability to execute code on cameras
- 18:42 Finding anonymous authentication endpoint
- 19:44 Number of vulnerable servers exposed online
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
We should do that, too. Good morning, DevCon. All right, we have our first talk of track three of the day. Uh, it's no emotion from Oh, jeez. [Applause] All right, let's get to it. Uh, no emotion from clarity team turning cameras surveillance on this ax. [Music] [Applause] >> Yeah, good job winning. Yeah, we kicked the asses. So, before I start, let me introduce myself. My name is Noah Mushe and I am the team lead and lead vulnerability researcher at Clarity 2. Now, my day job, and I believe it's one of the coolest there is, is to essentially find vulnerabilities in all sorts of devices and responsibly disclose them to the vendor. Here you can see one of I think six, seven racks in our lab where essentially this is my playground. I gets to connect and play and find vulnerabilities in all s…