← Vulnerability feed

Vulnerability record · CVE-2025-30025 · published 11 July 2025

CVE-2025-30025: Axis camera station pro deserialization of untrusted data vulnerability

Axis · Camera Station Pro

The communication protocol used between the server process and the service control had a flaw that could lead to a local privilege escalation.

4.8 CVSS 4.0 Medium EPSS 0.18% · top 93.0% CWE-502 · Deserialization of untrusted data
4.8CVSS 4.0 base score
0.18%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

The communication protocol used between the server process and the service control had a flaw that could lead to a local privilege escalation.

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-30025 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.0CVE-2025-30023Axis camera station deserialization of untrusted data vulnerabilityThe communication protocol used between client and server had a flaw that could lead to an authenticated user performing a remote code execution atta…EPSS 0.55%7.8CVE-2025-11547Axis camera station pro sensitive information in log file vulnerabilityAXIS Camera Station Pro contained a flaw to perform a privilege escalation attack on the server as a non-admin user.EPSS 0.15%7.3CVE-2025-0926Axis camera station pro incorrect permission assignment vulnerabilityGee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has found that it is possible for a non-admin user to remove system files causing a…EPSS 0.23%6.8CVE-2025-30024Axis device manager improper certificate validation vulnerabilityThe communication protocol used between client and server had a flaw that could be leveraged to execute a man in the middle attack.EPSS 0.36%6.5CVE-2025-1056Axis camera station pro vulnerabilityGee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has identified an issue with a specific file that the server is using. A non-admin …EPSS 0.24%6.3CVE-2024-7696Axis camera station pro vulnerabilitySeth Fogie, member of AXIS Camera Station Pro Bug Bounty Program, has found that it is possible for an authenticated malicious client to tamper with …EPSS 0.23%5.7CVE-2025-12063Axis camera station pro insecure direct object reference vulnerabilityAn insecure direct object reference allowed a non-admin user to modify or remove certain data objects without having the appropriate permissions.EPSS 0.20%5.3CVE-2025-30026Axis camera station authentication bypass via alternate path vulnerabilityThe AXIS Camera Station Server had a flaw that allowed to bypass authentication that is normally required.EPSS 0.62%

Source: NIST National Vulnerability Database (record CVE-2025-30025), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.