CVE-2025-11547

7.8

Axis Communications · AXIS Camera Station Pro

AXIS Camera Station Pro is vulnerable to a local privilege escalation flaw that allows a non-admin user to gain elevated server privileges.

Executive summary

A privilege escalation vulnerability in AXIS Camera Station Pro allows local non-admin users to gain unauthorized administrative access, posing a severe risk to system integrity.

Vulnerability

This vulnerability involves the insertion of sensitive information into log files (CWE-532), which can be leveraged by a local authenticated user with low privileges to escalate their access level to that of an administrator.

Business impact

Successful exploitation of this vulnerability allows a local attacker to bypass existing access controls and assume administrative authority over the camera management server. Given the CVSS score of 7.8, this represents a high-severity risk that could lead to unauthorized surveillance, manipulation of security footage, or the complete compromise of the physical security management environment.

Remediation

Immediate Action: Consult the official vendor security advisory provided by Axis Communications to identify the specific patched software release and apply the update immediately.

Proactive Monitoring: Audit system logs for unexpected privilege changes or unauthorized attempts to access restricted administrative functions by low-privilege accounts.

Compensating Controls: Restrict local access to the server hardware and limit the number of users with local login rights to minimize the attack surface.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability presents a significant risk to the security of the AXIS Camera Station Pro environment. Organizations should prioritize updating the affected software as soon as the vendor provides a remediation path, while simultaneously reviewing local access policies to ensure that only authorized personnel have the ability to interact with the host system.

Sources

Originally found and disclosed by Molybdenum, per the CVE Program record.