CVE-2025-30023
published 2025-07-11CVE-2025-30023: The communication protocol used between client and server had a flaw that could lead to an authenticated user performing a remote code execution attack.
PriorityP354critical9CVSS 3.1
AVAACLPRLUINSCCHIHAH
EPSS
0.50%
39.4th percentile
The communication protocol used between client and server had a flaw that could lead to an authenticated user performing a remote code execution attack.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| axis | camera_station | < 5.58.47195 | 5.58.47195 |
| axis | camera_station_pro | < 6.9.47069 | 6.9.47069 |
| axis | device_manager | < 5.32.137 | 5.32.137 |
| axis_communications_ab | axis_camera_station | — | — |
| axis_communications_ab | axis_camera_station_pro | — | — |
| axis_communications_ab | axis_device_manager | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2025-30023 is a deserialization of untrusted data (CWE-502) vulnerability in the client-server communication protocol of AXIS Camera Station Pro (<6.9), AXIS Camera Station (<5.58), and AXIS Device Manager (<5.32); an authenticated, adjacent-network attacker can achieve remote code execution — monitor for unexpected deserialization activity or process spawning from these server processes ↗
- →CVSS vector AV:A indicates the attack vector is adjacent network — detection should focus on lateral-movement scenarios within the same network segment targeting AXIS Camera Station / Device Manager server ports ↗
- →Scope is Changed (S:C) with high impact on Confidentiality, Integrity, and Availability — post-exploitation activity may extend beyond the compromised AXIS server process to other systems; monitor for unusual child processes or network connections originating from AXIS Camera Station server processes ↗
- ·Exploitation requires an authenticated user on the adjacent network (PR:L, AV:A); no public exploitation has been reported as of the advisory date ↗
- ·Affected version ranges: AXIS Camera Station Pro <6.9, AXIS Camera Station <5.58, AXIS Device Manager <5.32 — ensure version checks in detection logic account for these exact boundaries ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fjrg-m24m-jh2g: The communication protocol used between client and server had a flaw that could lead to an authenticated user performing a remote code execution attac
ghsa_unreviewed·2025-07-11
CVE-2025-30023 [CRITICAL] CWE-502 GHSA-fjrg-m24m-jh2g: The communication protocol used between client and server had a flaw that could lead to an authenticated user performing a remote code execution attac
The communication protocol used between client and server had a flaw that could lead to an authenticated user performing a remote code execution attack.
CISA ICS
Axis Communications Camera Station Pro, Camera Station, and Device Manager (Update B)
cisa_ics·2026-01-22·CVSS 9.0
[CRITICAL] Axis Communications Camera Station Pro, Camera Station, and Device Manager (Update B)
ICS Advisory
##
Axis Communications Camera Station Pro, Camera Station, and Device Manager (Update B)
Last RevisedJanuary 22, 2026
Alert CodeICSA-25-352-08
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## Summary
Successful exploitation of these vulnerabilities could result in an attacker executing arbitrary code, executing a man-in-middle style attack, or bypass authentication.
The following versions of Axis Communications Camera Station Pro, Camera Station, and Device Manager (Update B) are affected:
- AXIS Camera Station Pro (CVE-2025-30023, CVE-2025-30026)
- AXIS Camera Station Pro (CVE-2025-30025)
- AXIS Camera Station (CVE-2025-30023, CVE-2025-30026)
- AXIS Camera Station (CVE-2025-30025)
- AXIS De
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-07-11
Published