PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-30023 Axis Communications CVE debrief

Axis Communications and CISA describe a flaw in the communication protocol between client and server for AXIS Camera Station Pro, AXIS Camera Station, and AXIS Device Manager. An authenticated user could potentially leverage the issue to perform remote code execution. The supplied advisory rates the issue CVSS 3.1 9.0/CRITICAL (AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). Update B, published 2026-01-22, clarifies product versioning and the required mitigations.

Vendor
Axis Communications
Product
AXIS Camera Station Pro
CVSS
CRITICAL 9
CISA KEV
Not listed in stored evidence
Original CVE published
2025-12-18
Original CVE updated
2026-01-22
Advisory published
2025-12-18
Advisory updated
2026-01-22

Who should care

Administrators, security teams, and service providers responsible for AXIS Camera Station Pro, AXIS Camera Station, or AXIS Device Manager deployments, especially where authenticated users have access to the management interface.

Technical summary

The advisory says the client-server communication protocol contained a flaw that could permit remote code execution by an authenticated user. The supplied CSAF rates the issue as CVSS 3.1 9.0/Critical with low attack complexity, no user interaction, elevated privileges required, and high confidentiality, integrity, and availability impact. CISA’s Update B revision states that affected products/versioning and mitigations were clarified.

Defensive priority

Urgent. Patch affected Axis management systems as soon as practical because this is an authenticated remote code execution issue with critical impact.

Recommended defensive actions

  • Upgrade AXIS Camera Station Pro to 6.9 or later.
  • Upgrade AXIS Camera Station to 5.58 or later.
  • Upgrade AXIS Device Manager to 5.32 or later.
  • Verify the exact affected product/version mapping against the CISA CSAF advisory Update B before and after remediation.
  • Apply CISA industrial control system defense-in-depth and recommended practices to the systems that host these products.

Evidence notes

This debrief is based on the CISA CSAF advisory ICSA-25-352-08 (CVE-2025-30023), published 2025-12-18 and revised on 2026-01-15 and 2026-01-22. The advisory states the flaw could lead to authenticated remote code execution. The supplied corpus does not list this CVE in KEV and does not attribute ransomware use.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-30023 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-30023

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-30023 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-30023

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-352-08.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-352-08

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.