cbcvebase.
CVE-2025-30023
published 2025-07-11

CVE-2025-30023: The communication protocol used between client and server had a flaw that could lead to an authenticated user performing a remote code execution attack.

PriorityP354critical9CVSS 3.1
AVAACLPRLUINSCCHIHAH
EPSS
0.50%
39.4th percentile
The communication protocol used between client and server had a flaw that could lead to an authenticated user performing a remote code execution attack.

Affected

6 ranges
VendorProductVersion rangeFixed in
axiscamera_station< 5.58.471955.58.47195
axiscamera_station_pro< 6.9.470696.9.47069
axisdevice_manager< 5.32.1375.32.137
axis_communications_abaxis_camera_station
axis_communications_abaxis_camera_station_pro
axis_communications_abaxis_device_manager

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2025-30023 is a deserialization of untrusted data (CWE-502) vulnerability in the client-server communication protocol of AXIS Camera Station Pro (<6.9), AXIS Camera Station (<5.58), and AXIS Device Manager (<5.32); an authenticated, adjacent-network attacker can achieve remote code execution — monitor for unexpected deserialization activity or process spawning from these server processes
  • CVSS vector AV:A indicates the attack vector is adjacent network — detection should focus on lateral-movement scenarios within the same network segment targeting AXIS Camera Station / Device Manager server ports
  • Scope is Changed (S:C) with high impact on Confidentiality, Integrity, and Availability — post-exploitation activity may extend beyond the compromised AXIS server process to other systems; monitor for unusual child processes or network connections originating from AXIS Camera Station server processes
  • ·Exploitation requires an authenticated user on the adjacent network (PR:L, AV:A); no public exploitation has been reported as of the advisory date
  • ·Affected version ranges: AXIS Camera Station Pro <6.9, AXIS Camera Station <5.58, AXIS Device Manager <5.32 — ensure version checks in detection logic account for these exact boundaries
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.