CVE-2025-30023 is a critical remote code execution vulnerability affecting Axis Camera Station, Camera Station Pro, and Device Manager. This flaw in the client-server communication protocol allows an authenticated attacker on the adjacent network to execute arbitrary code with high impact on confidentiality, integrity, and availability. While there is no public exploit code or evidence of active exploitation, the vulnerability has garnered significant community discussion and media attention, indicating a high level of interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.58.47195CPE matchmatch criteria | cpe:2.3:a:axis:camera_station:*:*:*:*:*:*:*:* | ||
< 6.9.47069CPE matchmatch criteria | cpe:2.3:a:axis:camera_station_pro:*:*:*:*:*:*:*:* | ||
< 5.32.137CPE matchmatch criteria | cpe:2.3:a:axis:device_manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.3 Reddit, 0.3 Bluesky, 0.4 Mastodon, and 2.6 GitHub mentions.
The average CVE in this peer group has 0.9 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.