VYPR
Medium severity4.5NVD Advisory· Published Feb 10, 2026· Updated Jun 17, 2026

CVE-2025-13064

CVE-2025-13064

Description

A server-side injection was possible for a malicious admin to manipulate the application to include a malicious script which is executed by the server. This attack is only possible if the admin uses a client that have been tampered with.

Affected products

3
  • cpe:2.3:a:axis:camera_station_pro:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:axis:camera_station_pro:*:*:*:*:*:*:*:*range: <6.14.10768
    • (no CPE)range: 6
  • Axis/Axisllm-fuzzy

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.