CVE-2025-12757 Details
Description
An AXIS Camera Station Pro feature can be exploited in a way that allows a non-admin user to view information they are not permitted to.
A vulnerability exists in Axis Camera Station Pro versions prior to 6.14, allowing non-admin users to access information they are not authorized to view. This issue arises from improper restrictions on user permissions within the application.
Users are advised to update to Axis Camera Station Pro version 6.14, which addresses this vulnerability. The latest version can be obtained from the Axis vulnerability management portal. For further assistance, contact Axis Technical Support.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.axis.com/dam/public/de/38/d3/cve-2025-12757pdf-en-US-519289.pdf | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| axis camera station pro | < 6.14.10768 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 17, 2026 | Initial Analysis | [email protected] |
| Feb 10, 2026 | New CVE Received | [email protected] |