A server-side injection was possible for a malicious admin to manipulate the application to include a malicious script which is executed by the server. This attack is only possible if the admin uses a client that have been tampered with.
History

Tue, 10 Feb 2026 06:00:00 +0000

Type Values Removed Values Added
Description A server-side injection was possible for a malicious admin to manipulate the application to include a malicious script which is executed by the server. This attack is only possible if the admin uses a client that have been tampered with.
First Time appeared Axis Communications Ab
Axis Communications Ab axis Camera Station Pro
Weaknesses CWE-248
CPEs cpe:2.3:a:axis_communications_ab:axis_camera_station_pro:*:*:*:*:*:*:*:*
Vendors & Products Axis Communications Ab
Axis Communications Ab axis Camera Station Pro
References
Metrics cvssV3_1

{'score': 4.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Axis

Published:

Updated: 2026-02-10T05:40:34.374Z

Reserved: 2025-11-12T13:05:30.353Z

Link: CVE-2025-13064

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-02-10T06:15:54.170

Modified: 2026-02-10T06:15:54.170

Link: CVE-2025-13064

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.