Gee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has identified an issue with a specific file that the server is using. A non-admin user can modify this file to either create files or change the content of files in an admin-protected location.
Axis has released a patched version for the highlighted flaw. Please 
refer to the Axis security advisory for more information and solution.
                
            Metrics
Affected Vendors & Products
References
        History
                    Wed, 23 Apr 2025 13:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Wed, 23 Apr 2025 05:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Gee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has identified an issue with a specific file that the server is using. A non-admin user can modify this file to either create files or change the content of files in an admin-protected location. Axis has released a patched version for the highlighted flaw. Please refer to the Axis security advisory for more information and solution. | |
| Weaknesses | CWE-73 | |
| References |  | |
| Metrics | cvssV3_1 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: Axis
Published: 2025-04-23T05:18:10.120Z
Updated: 2025-04-23T13:09:33.255Z
Reserved: 2025-02-05T07:29:10.344Z
Link: CVE-2025-1056
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-04-23T13:09:28.474Z
 NVD
                        NVD
                    Status : Awaiting Analysis
Published: 2025-04-23T06:15:46.573
Modified: 2025-04-23T14:08:13.383
Link: CVE-2025-1056
 Redhat
                        Redhat
                    No data.