← Vulnerability feed

Vulnerability record · CVE-2025-30026 · published 11 July 2025

CVE-2025-30026: Axis camera station authentication bypass via alternate path vulnerability

Axis · Camera Station

The AXIS Camera Station Server had a flaw that allowed to bypass authentication that is normally required.

5.3 CVSS 4.0 Medium EPSS 0.62% · top 52.5% CWE-288 · Authentication bypass via alternate path
5.3CVSS 4.0 base score
0.62%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

The AXIS Camera Station Server had a flaw that allowed to bypass authentication that is normally required.

CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-30026 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.0CVE-2025-30023Axis camera station deserialization of untrusted data vulnerabilityThe communication protocol used between client and server had a flaw that could lead to an authenticated user performing a remote code execution atta…EPSS 0.55%7.8CVE-2025-11547Axis camera station pro sensitive information in log file vulnerabilityAXIS Camera Station Pro contained a flaw to perform a privilege escalation attack on the server as a non-admin user.EPSS 0.15%7.3CVE-2025-0926Axis camera station pro incorrect permission assignment vulnerabilityGee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has found that it is possible for a non-admin user to remove system files causing a…EPSS 0.23%6.5CVE-2025-1056Axis camera station pro vulnerabilityGee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has identified an issue with a specific file that the server is using. A non-admin …EPSS 0.24%6.3CVE-2024-7696Axis camera station pro vulnerabilitySeth Fogie, member of AXIS Camera Station Pro Bug Bounty Program, has found that it is possible for an authenticated malicious client to tamper with …EPSS 0.23%5.7CVE-2025-12063Axis camera station pro insecure direct object reference vulnerabilityAn insecure direct object reference allowed a non-admin user to modify or remove certain data objects without having the appropriate permissions.EPSS 0.20%5.1CVE-2025-7622Axis camera station server-side request forgery (ssrf) vulnerabilityDuring an internal security assessment, a Server-Side Request Forgery (SSRF) vulnerability that allowed an authenticated attacker to access internal …EPSS 0.17%4.8CVE-2025-30025Axis camera station pro deserialization of untrusted data vulnerabilityThe communication protocol used between the server process and the service control had a flaw that could lead to a local privilege escalation.EPSS 0.18%

Source: NIST National Vulnerability Database (record CVE-2025-30026), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.