CVE-2025-13064
Undergoing Analysis Undergoing Analysis - In Progress

Server-Side Injection via Malicious Admin in Axis Software

Vulnerability report for CVE-2025-13064, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-02-10

Last updated on: 2026-02-17

Assigner: Axis Communications AB

Description

A server-side injection was possible for a malicious admin to manipulate the application to include a malicious script which is executed by the server. This attack is only possible if the admin uses a client that have been tampered with.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-02-10
Last Modified
2026-02-17
Generated
2026-07-26
AI Q&A
2026-02-10
EPSS Evaluated
2026-07-25
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
axis camera_station_pro to 6.14.10768 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-248 An exception is thrown from a function, but it is not caught.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a server-side injection that allows a malicious administrator to manipulate the application to include and execute a malicious script on the server.

However, this attack can only occur if the administrator uses a client that has been tampered with.

Detection Guidance

I don't know

Impact Analysis

The vulnerability can lead to the execution of malicious scripts on the server, potentially causing denial of service or other disruptions.

Since the CVSS score indicates a high impact on availability (A:H) but no impact on confidentiality or integrity, the main risk is service disruption rather than data compromise.

Compliance Impact

I don't know

Mitigation Strategies

I don't know

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-13064. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart