CVE-2025-30026

The AXIS Camera Station Server had a flaw that allowed to bypass authentication that is normally required.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:axis:camera_station:*:*:*:*:*:*:*:*
cpe:2.3:a:axis:camera_station_pro:*:*:*:*:*:*:*:*

History

16 Jan 2026, 14:56

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CPE cpe:2.3:a:axis:camera_station:*:*:*:*:*:*:*:*
cpe:2.3:a:axis:camera_station_pro:*:*:*:*:*:*:*:*
References () https://www.axis.com/dam/public/a3/42/92/cve-2025-30026pdf-en-US-485735.pdf - () https://www.axis.com/dam/public/a3/42/92/cve-2025-30026pdf-en-US-485735.pdf - Vendor Advisory
First Time Axis camera Station
Axis
Axis camera Station Pro

15 Jul 2025, 13:14

Type Values Removed Values Added
Summary
  • (es) El servidor AXIS Camera Station tenía una falla que permitía eludir la autenticación que normalmente se requiere.

11 Jul 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-11 06:15

Updated : 2026-01-16 14:56


NVD link : CVE-2025-30026

Mitre link : CVE-2025-30026

CVE.ORG link : CVE-2025-30026


JSON object : View

Products Affected

axis

  • camera_station
  • camera_station_pro
CWE
CWE-288

Authentication Bypass Using an Alternate Path or Channel