Work at AXIS OS? Claim it to respond to reviews as the verified owner.
Found a vulnerability?
If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.
Ask BugRater to submit itPrivate. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.
Reviews
0 publishedNo reviews yet.
Facts published by Bugcrowd on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 19 Sep 2026.
Axis Communications acknowledges the importance and hard work performed by security researchers. Thank you for working with us to help increase the security in our products and joining into our program! Report Assessment and Bounty Calculations: This program will use the CVSS v3.1 rating system (Common Vulnerability Scoring System). Axis may assess the vulnerability accordingly to its relevance in the context of how Axis recommends deploying its products, software, and services. In any instance where an issue is downgraded or upgraded, a full, detailed explanation will be provided. Axis will validate all submissions on latest device software available on axis.com. P1 = CVSSv3.1 critical (9.0 – 10.0) P2 = CVSSv3.1 high (7.0 – 8.9) P3 = CVSSv3.1 medium (4.0 – 6.9) P4 = CVSSv3.1 low (0.1 – 3.9) Reward payout: Rewards are paid out directly once the submission is accepted as valid submission. Researchers will also receive a one-time-only swag reward in form of a AXIS M1075-L free of charge (MSRP $350) for submissions that result in a CVE-ID. An additional bonus of up to $10.000 may be rewarded for exceptional submissions to Axis discretion. The maximum bonus will always be rewarded in accepted P1/Critical submissions. Bypass reward We welcome submissions that can bypass previously disclosed AXIS OS CVEs. If your submission is deemed valid, you will be eligible for a one-time reward of $500 per CVE. If you share new insights or techniques that increase the impact of the CVE, we'll reassess the vulnerability. In these cases, the payout will match the updated severity level, which could exceed the $500 reward. Disclosure Policy: Axis as authorized Common Vulnerability and Exposures (CVE) Numbering Authority (CNA) discloses all vulnerabilities found in the Bug Bounty Program accordingly as outlined in the Axis Vulnerability Management Policy. Eligibility and Fairness: To maintain the integrity and fairness of our bug bounty program, individuals who are currently employed by Axis or who were previously employed by Axis, are not eligible to receive rewards for vulnerabilities identified through the use of internal knowledge gained during their employment. If you are aware of a vulnerability as a result of current or past employment, we still encourage you to disclose it responsibly. While such reports may not qualify for a monetary reward, they will be reviewed and addressed with the same level of priority as all other submissions. We appreciate your cooperation in helping us ensure a transparent and equitable program for the wider security research community. By participating in this program, you acknowledge and agree that Axis may enforce Bugcrowd’s Standard Disclosure Terms if you breach any provision therein. Axis EULA applies when accessing Axis devices through the Bug Bounty Program.
Scope
1 asset| Asset | Type | Eligibility | Max severity |
|---|---|---|---|
| AXIS OS | iot | ✓ bounty | not set |