The Axis Remote Access Architecture
Noam Moshe set out to hack into internal networks of big companies. While scanning Shodan, he found Axis Remoting, a proprietary protocol for remote camera management. Axis is the dominant IP camera vendor for enterprises, governments, and medical institutions. Their cameras run Axis OS, a customized Linux fork. The Axis Device Manager provides centralized fleet control. The Axis Camera Station enables live video surveillance. For remote access, Axis implemented a fully encrypted, authenticated protocol exposed on the internet.
Deserialization Bug in the .NET RPC Protocol
Axis Device Manager uses .NET Windows applications with MTLS-wrapped communication. The protocol requires NLM SSP authentication and exposes the server’s hostname during handshake. After authentication, JSON-based RPC invokes server methods. Moshe discovered the server uses JSON deserialization with TypeNameHandling.Auto, letting the client specify arbitrary classes to create on the server. This deserialization vulnerability in .NET, using known gadgets, yields remote code execution on both server and client.
Fallback Protocol Enables Pre-Authentication Exploitation
The deserialization bug required credentials, so Moshe used pass-the-hash through his MITM setup. He then found a fallback protocol on a different port. This protocol uses HTTP with custom encryption, two channels (TX and RX), and RSA key exchange. Critically, a hidden endpoint at “//” accepts anonymous authentication. This bypasses the NLM requirement entirely, enabling pre-authentication RCE on the Axis server and all cameras it manages.
Impact and Responsible Disclosure
Moshe found nearly 6,500 Axis Remoting servers exposed online, mostly in the US. Each server manages up to 10,000 cameras. Using the NLM hostname leak, he identified targets including educational institutions, government agencies, medical facilities, and large companies. Recent bans on Chinese camera brands leave fewer options, and organizations assume encryption equals security. Moshe responsibly disclosed all vulnerabilities to Axis, who implemented patches quickly.
Notable Quotes
fully encrypted, fully authenticated, fully secure or maybe not so much Noam Moshe · ▶ 4:39
almost 6,500 different servers around the world, most of which are in the US Noam Moshe · ▶ 19:43
super super deep secret endpoint which is slash slash which for some reason I’m not sure why supports the anonymous authentication schema Noam Moshe · ▶ 18:31
Key Takeaways
- JSON deserialization vulnerability in Axis Remoting protocol yields pre-authentication RCE.
- Hidden “//” endpoint accepts anonymous authentication, bypassing NLM requirements entirely.
- 6,500 exposed Axis servers manage up to 10,000 cameras each, affecting organizations worldwide.
About the Speaker(s)
Noam Moshe is a vulnerability researcher and Team Lead at Claroty Team82. He specializes in vulnerability research, web applications pentesting, malware analysis, network forensics and ICS/SCADA security. He has presented at Black Hat and DEF CON, and won Master of Pwn at Pwn2Own Miami 2023.