← Vulnerability feed

Vulnerability record · CVE-2025-30023 · published 11 July 2025

CVE-2025-30023: Axis camera station deserialization of untrusted data vulnerability

Axis · Camera Station

The communication protocol used between client and server had a flaw that could lead to an authenticated user performing a remote code execution attack.

9.0 CVSS 3.1 Critical EPSS 0.59% · top 53.8% CWE-502 · Deserialization of untrusted data
9.0CVSS 3.1 base score
0.59%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

The communication protocol used between client and server had a flaw that could lead to an authenticated user performing a remote code execution attack.

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-30023 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2025-11547Axis camera station pro sensitive information in log file vulnerabilityAXIS Camera Station Pro contained a flaw to perform a privilege escalation attack on the server as a non-admin user.EPSS 0.16%7.3CVE-2025-0926Axis camera station pro incorrect permission assignment vulnerabilityGee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has found that it is possible for a non-admin user to remove system files causing a…EPSS 0.23%6.8CVE-2025-30024Axis device manager improper certificate validation vulnerabilityThe communication protocol used between client and server had a flaw that could be leveraged to execute a man in the middle attack.EPSS 0.36%6.5CVE-2025-1056Axis camera station pro vulnerabilityGee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has identified an issue with a specific file that the server is using. A non-admin …EPSS 0.24%6.3CVE-2024-7696Axis camera station pro vulnerabilitySeth Fogie, member of AXIS Camera Station Pro Bug Bounty Program, has found that it is possible for an authenticated malicious client to tamper with …EPSS 0.23%5.7CVE-2025-12063Axis camera station pro insecure direct object reference vulnerabilityAn insecure direct object reference allowed a non-admin user to modify or remove certain data objects without having the appropriate permissions.EPSS 0.19%5.3CVE-2025-30026Axis camera station authentication bypass via alternate path vulnerabilityThe AXIS Camera Station Server had a flaw that allowed to bypass authentication that is normally required.EPSS 0.62%5.3CVE-2021-31989Axis device manager cleartext storage of sensitive data vulnerabilityA user with permission to log on to the machine hosting the AXIS Device Manager client could under certain conditions extract a memory dump from the …EPSS 0.40%

Source: NIST National Vulnerability Database (record CVE-2025-30023), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.