CVE-2025-30025

The communication protocol used between the server process and the service control had a flaw that could lead to a local privilege escalation.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:axis:camera_station_pro:*:*:*:*:*:*:*:*
cpe:2.3:a:axis:device_manager:*:*:*:*:*:*:*:*

History

23 Jan 2026, 21:49

Type Values Removed Values Added
CPE cpe:2.3:a:axis:device_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:axis:camera_station_pro:*:*:*:*:*:*:*:*
First Time Axis
Axis camera Station Pro
Axis device Manager
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
References () https://www.axis.com/dam/public/f2/28/d2/cve-2025-30025pdf-en-US-517962.pdf - () https://www.axis.com/dam/public/f2/28/d2/cve-2025-30025pdf-en-US-517962.pdf - Vendor Advisory

07 Jan 2026, 12:17

Type Values Removed Values Added
References
  • {'url': 'https://www.axis.com/dam/public/40/0e/03/cve-2025-30025pdf-en-US-485736.pdf', 'source': 'product-security@axis.com'}
  • () https://www.axis.com/dam/public/f2/28/d2/cve-2025-30025pdf-en-US-517962.pdf -

15 Jul 2025, 13:14

Type Values Removed Values Added
Summary
  • (es) El protocolo de comunicación utilizado entre el proceso del servidor y el control del servicio tenía una falla que podría conducir a una escalada de privilegios locales.

11 Jul 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-11 06:15

Updated : 2026-01-23 21:49


NVD link : CVE-2025-30025

Mitre link : CVE-2025-30025

CVE.ORG link : CVE-2025-30025


JSON object : View

Products Affected

axis

  • camera_station_pro
  • device_manager
CWE
CWE-502

Deserialization of Untrusted Data