CVE-2025-30025
published 2025-07-11CVE-2025-30025: The communication protocol used between the server process and the service control had a flaw that could lead to a local privilege escalation.
PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.18%
7.6th percentile
The communication protocol used between the
server process and the service control had a flaw that could lead to a local privilege escalation.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| axis | camera_station_pro | < 6.8.43213 | 6.8.43213 |
| axis | device_manager | < 5.32.137 | 5.32.137 |
| axis_communications_ab | axis_camera_station | — | — |
| axis_communications_ab | axis_camera_station_pro | — | — |
| axis_communications_ab | axis_device_manager | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.04.8MEDIUMCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vjrh-7rvq-8ghw: The communication protocol used between the
server process and the service control had a flaw that could lead to a local privilege escalation
ghsa_unreviewed·2025-07-11
CVE-2025-30025 [MEDIUM] CWE-502 GHSA-vjrh-7rvq-8ghw: The communication protocol used between the
server process and the service control had a flaw that could lead to a local privilege escalation
The communication protocol used between the
server process and the service control had a flaw that could lead to a local privilege escalation.
CISA ICS
Axis Communications Camera Station Pro, Camera Station, and Device Manager (Update B)
cisa_ics·2026-01-22·CVSS 9.0
[CRITICAL] Axis Communications Camera Station Pro, Camera Station, and Device Manager (Update B)
ICS Advisory
##
Axis Communications Camera Station Pro, Camera Station, and Device Manager (Update B)
Last RevisedJanuary 22, 2026
Alert CodeICSA-25-352-08
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## Summary
Successful exploitation of these vulnerabilities could result in an attacker executing arbitrary code, executing a man-in-middle style attack, or bypass authentication.
The following versions of Axis Communications Camera Station Pro, Camera Station, and Device Manager (Update B) are affected:
- AXIS Camera Station Pro (CVE-2025-30023, CVE-2025-30026)
- AXIS Camera Station Pro (CVE-2025-30025)
- AXIS Camera Station (CVE-2025-30023, CVE-2025-30026)
- AXIS Camera Station (CVE-2025-30025)
- AXIS De
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-07-11
Published