📦

camera_station_pro

Vendor: axis

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 1 Remote Access
Total CVEs 22 Total Indexed
Avg. EPSS 0.26% Exploit Prob.
Latest CVE CVE-2025-12063 Feb 10

Security Vulnerability Index

Page 1 / 3
5.7 CVSS

An insecure direct object reference allowed a non-admin user to modify or remove certain data objects without having the appropriate permissions.

EPSS: 0.19%
4.5 CVSS

A server-side injection was possible for a malicious admin to manipulate the application to include a malicious script which is executed by the server. This attack is only possible if the admin uses a client that have been tampered with.

EPSS: 0.23%
4.6 CVSS

An AXIS Camera Station Pro feature can be exploited in a way that allows a non-admin user to view information they are not permitted to.

EPSS: 0.27%
7.8 CVSS

AXIS Camera Station Pro contained a flaw to perform a privilege escalation attack on the server as a non-admin user.

EPSS: 0.15%
5.1 CVSS

During an internal security assessment, a Server-Side Request Forgery (SSRF) vulnerability that allowed an authenticated attacker to access internal resources on the server was discovered.

EPSS: 0.16%
5.3 CVSS

The AXIS Camera Station Server had a flaw that allowed to bypass authentication that is normally required.

EPSS: 0.60%
4.8 CVSS

The communication protocol used between the server process and the service control had a flaw that could lead to a local privilege escalation.

EPSS: 0.18%
9.0 CVSS

The communication protocol used between client and server had a flaw that could lead to an authenticated user performing a remote code execution attack.

EPSS: 0.50%
6.1 CVSS

Gee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has identified an issue with a specific file that the server is using. A non-admin user can modify this file to either create files or change the content of files in an admin-protected location. Axis has released a patched version for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.

EPSS: 0.21%
5.9 CVSS

Gee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has found that it is possible for a non-admin user to remove system files causing a boot loop by redirecting a file deletion when recording video. Axis has released a patched version for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.

EPSS: 0.20%