A server-side injection was possible for a malicious admin to manipulate the application to include a malicious script which is executed by the server. This attack is only possible if the admin uses a client that have been tampered with.
References
| Link | Resource |
|---|---|
| https://www.axis.com/dam/public/a9/9e/94/cve-2025-13064pdf-en-US-519290.pdf | Vendor Advisory |
Configurations
History
17 Feb 2026, 15:10
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.axis.com/dam/public/a9/9e/94/cve-2025-13064pdf-en-US-519290.pdf - Vendor Advisory | |
| CPE | cpe:2.3:a:axis:camera_station_pro:*:*:*:*:*:*:*:* | |
| Summary |
|
|
| First Time |
Axis
Axis camera Station Pro |
10 Feb 2026, 06:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-10 06:15
Updated : 2026-02-17 15:10
NVD link : CVE-2025-13064
Mitre link : CVE-2025-13064
CVE.ORG link : CVE-2025-13064
JSON object : View
Products Affected
axis
- camera_station_pro
CWE
CWE-248
Uncaught Exception
