CVE-2025-12063
- EPSS 0.01%
- Veröffentlicht 10.02.2026 05:52:35
- Zuletzt bearbeitet 17.02.2026 15:09:06
An insecure direct object reference allowed a non-admin user to modify or remove certain data objects without having the appropriate permissions.
CVE-2025-12757
- EPSS 0.01%
- Veröffentlicht 10.02.2026 05:47:20
- Zuletzt bearbeitet 17.02.2026 15:10:09
An AXIS Camera Station Pro feature can be exploited in a way that allows a non-admin user to view information they are not permitted to.
CVE-2025-13064
- EPSS 0.01%
- Veröffentlicht 10.02.2026 05:40:34
- Zuletzt bearbeitet 17.02.2026 15:10:00
A server-side injection was possible for a malicious admin to manipulate the application to include a malicious script which is executed by the server. This attack is only possible if the admin uses a client that have been tampered with.
CVE-2025-11547
- EPSS 0.01%
- Veröffentlicht 10.02.2026 05:35:50
- Zuletzt bearbeitet 17.02.2026 15:10:57
AXIS Camera Station Pro contained a flaw to perform a privilege escalation attack on the server as a non-admin user.
CVE-2025-7622
- EPSS 0.02%
- Veröffentlicht 12.08.2025 05:15:32
- Zuletzt bearbeitet 13.01.2026 18:46:46
During an internal security assessment, a Server-Side Request Forgery (SSRF) vulnerability that allowed an authenticated attacker to access internal resources on the server was discovered.
- EPSS 2.57%
- Veröffentlicht 11.07.2025 06:15:24
- Zuletzt bearbeitet 23.01.2026 21:14:03
The communication protocol used between client and server had a flaw that could lead to an authenticated user performing a remote code execution attack.
CVE-2025-30025
- EPSS 0.1%
- Veröffentlicht 11.07.2025 06:15:24
- Zuletzt bearbeitet 23.01.2026 21:49:32
The communication protocol used between the server process and the service control had a flaw that could lead to a local privilege escalation.
CVE-2025-30026
- EPSS 0.08%
- Veröffentlicht 11.07.2025 06:15:24
- Zuletzt bearbeitet 16.01.2026 14:56:23
The AXIS Camera Station Server had a flaw that allowed to bypass authentication that is normally required.
CVE-2025-0926
- EPSS 0.11%
- Veröffentlicht 23.04.2025 05:22:03
- Zuletzt bearbeitet 14.01.2026 17:45:54
Gee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has found that it is possible for a non-admin user to remove system files causing a boot loop by redirecting a file deletion when recording video. Axis has released a patched version f...
CVE-2025-1056
- EPSS 0.19%
- Veröffentlicht 23.04.2025 05:18:10
- Zuletzt bearbeitet 14.01.2026 17:41:50
Gee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has identified an issue with a specific file that the server is using. A non-admin user can modify this file to either create files or change the content of files in an admin-protected...