Cybersecurity researchers have uncovered a cluster of serious vulnerabilities in Axis Communications’ surveillance infrastructure, affecting both server and client components. The flaws, if exploited, could lead to full system takeovers—placing the privacy and security of monitored environments in jeopardy.
The Scope: Thousands Exposed to Potential Attacks
Claroty’s research unveils that over 6,500 servers exposing the proprietary Axis. Remoting protocol are accessible via the internet. Alarmingly, nearly 4,000 of these servers are located in the U.S., highlighting a significant geolocation-based risk.
Vulnerabilities at a Glance
The team identified four major vulnerabilities, each with varying degrees of severity:
- CVE-2025-30023 (CVSS 9.0): A flaw in the client–server communication protocol enabling remote code execution (RCE) post-authentication. Patched in Camera Station Pro 6.9, Camera Station 5.58, and Device Manager 5.32.
- CVE-2025-30024 (CVSS 6.8): Vulnerable to adversary-in-the-middle (AiTM) attacks, intercepted via protocol manipulation. Fixed in Device Manager 5.32.
- CVE-2025-30025 (CVSS 4.8): Allows local privilege escalation through a flaw in the communication between server processes and service control. Fixed in Camera Station Pro 6.8 and Device Manager 5.32.
- CVE-2025-30026 (CVSS 5.3): Enables authentication bypass in the Axis Camera Station Server. Resolved in Camera Station Pro 6.9 and Camera Station 5.58.
Potential Attack Scenarios
If exploited, these vulnerabilities empower attackers to position themselves as AiTM between Camera Station clients and servers. This enables them to tamper with requests and responses, execute arbitrary commands, manipulate camera feeds, and even commandeer system-level access on internal networks.
Claroty’s Noam Moshe warned: “Feeds can be hijacked, watched, and/or shut down… Successful exploits give attackers system‑level access … to control each of the cameras within a specific deployment”.
To date, there is no evidence of these vulnerabilities being exploited in the wild, but the level of exposure and access risk warrant immediate attention.
Axis Communications’ Response & User Guidance
Axis has released updates in Camera Station Pro, Camera Station, and Device Manager to address all reported issues. Users are strongly urged to patch systems promptly:
| Component | Minimum Safe Version |
|---|---|
| Camera Station Pro | 6.9 |
| Camera Station | 5.58 |
| Device Manager | 5.32 |
Running earlier versions leaves systems exposed to attacks ranging from RCE to authentication bypasses.
Mitigation Measures Beyond Patching
While the primary defense is updating to the patched releases, organizations should also:
- Limit external exposure: Avoid directly exposing Axis.Remoting services to the internet when possible.
- Control access: Restrict public-facing access to management interfaces via firewalls or VPNs.
- Monitor for anomalies: Track unusual access or connection patterns to Axis services.
These defensive steps complement patching to reduce attack surfaces and mitigate risk.
Looking Ahead
This incident underscores a critical lesson for surveillance and IoT device users: security must extend beyond deployment. Remote management systems and video management solutions cannot be overlooked. As Axis users upgrade their systems, defenders must also reassess their broader network and device exposure—even for trusted internal tools.
With thousands of vulnerable servers live across global and domestic environments, timely updates and diligent monitoring are non-negotiable.
Please subscribe to the Newsletter so that you do not miss any critical update
