CVE-2025-13064: Medium severity Axis Camera Station Pro vulnerability
A server-side injection was possible for a malicious admin to manipulate the application to include a malicious script which is executed by the server. This attack is only possible if the admin uses a client that have been tampered with.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13064?
CVE-2025-13064 is considered a critical vulnerability due to its potential for server-side injection by a malicious admin.
How do I fix CVE-2025-13064?
To mitigate CVE-2025-13064, ensure that administrative users access the application using untampered clients and update the software to the latest version.
Who is affected by CVE-2025-13064?
CVE-2025-13064 affects users of Axis Camera Station Pro versions prior to 6.14.10768.
What type of attack is CVE-2025-13064 associated with?
CVE-2025-13064 is associated with a server-side injection attack that can be exploited by malicious administrators.
What are the potential consequences of CVE-2025-13064?
The consequences of CVE-2025-13064 may include unauthorized execution of scripts on the server, leading to data compromise and potential system takeover.