CVE-2025-30026
published 2025-07-11CVE-2025-30026: The AXIS Camera Station Server had a flaw that allowed to bypass authentication that is normally required.
PriorityP264critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.60%
44.5th percentile
The AXIS Camera Station Server had a flaw that allowed
to bypass authentication that is normally required.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| axis | camera_station | < 5.58.47195 | 5.58.47195 |
| axis | camera_station_pro | >= 6.0.25729 < 6.9.47069 | 6.9.47069 |
| axis_communications_ab | axis_camera_station | — | — |
| axis_communications_ab | axis_camera_station_pro | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2025-30026 affects AXIS Camera Station Server (Pro <6.9, Camera Station <5.58) and allows authentication bypass via an alternate path or channel (CWE-288); detect unauthenticated or anomalous access attempts to the Camera Station Server from adjacent network segments ↗
- →CVE-2025-30026 has CVSS vector AV:A (adjacent network), AC:L, PR:N — monitor for unauthenticated connections to AXIS Camera Station Server ports originating from adjacent/LAN segments without prior authentication handshake ↗
- ·Affected versions for CVE-2025-30026: AXIS Camera Station Pro versions below 6.9 and AXIS Camera Station versions below 5.58 are vulnerable; fixed in Pro 6.9+ and Camera Station 5.58+ ↗
- ·No known public exploitation of CVE-2025-30026 has been reported at time of advisory publication ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.05.3MEDIUMCVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Axis Communications Camera Station Pro, Camera Station, and Device Manager (Update B)
cisa_ics·2026-01-22·CVSS 9.0
[CRITICAL] Axis Communications Camera Station Pro, Camera Station, and Device Manager (Update B)
ICS Advisory
##
Axis Communications Camera Station Pro, Camera Station, and Device Manager (Update B)
Last RevisedJanuary 22, 2026
Alert CodeICSA-25-352-08
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## Summary
Successful exploitation of these vulnerabilities could result in an attacker executing arbitrary code, executing a man-in-middle style attack, or bypass authentication.
The following versions of Axis Communications Camera Station Pro, Camera Station, and Device Manager (Update B) are affected:
- AXIS Camera Station Pro (CVE-2025-30023, CVE-2025-30026)
- AXIS Camera Station Pro (CVE-2025-30025)
- AXIS Camera Station (CVE-2025-30023, CVE-2025-30026)
- AXIS Camera Station (CVE-2025-30025)
- AXIS De
GHSA
GHSA-68rg-v3m3-f4hp: The AXIS Camera Station Server had a flaw that allowed
to bypass authentication that is normally required
ghsa_unreviewed·2025-07-11
CVE-2025-30026 [MEDIUM] CWE-288 GHSA-68rg-v3m3-f4hp: The AXIS Camera Station Server had a flaw that allowed
to bypass authentication that is normally required
The AXIS Camera Station Server had a flaw that allowed
to bypass authentication that is normally required.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-07-11
Published