Source: The Hacker News
Author: info@thehackernews.com (The Hacker News)
URL: https://thehackernews.com/2025/08/6500-axis-servers-expose-remoting.html
ONE SENTENCE SUMMARY:
Security researchers identified multiple vulnerabilities in Axis Communications’ video surveillance products, enabling potential remote code execution and unauthorized access.
MAIN POINTS:
- Security flaws disclosed in Axis Communications’ video surveillance products.
- Vulnerabilities could lead to takeover attacks when exploited.
- Remote code execution possible on Axis Device Manager and Camera Station.
- Internet scans reveal 6,500 servers using vulnerable Axis.Remoting services.
- Four main CVEs identified with varying severity (CVSS scores 9.0 to 4.8).
- Exploits allow adversary-in-the-middle and authentication bypass attacks.
- Over 4,000 vulnerable servers are located in the U.S.
- Attackers can hijack and control camera feeds.
- Successful exploitation grants system-level access to internal networks.
- Currently, no wild exploitation of these vulnerabilities has been reported.
TAKEAWAYS:
- CVE-2025-30023 is critically severe with a score of 9.0.
- Authentication bypass vulnerability poses significant security risk.
- Patching systems with updated software versions is crucial.
- Awareness of server exposure to Axis.Remoting services is important.
- Vigilance needed as no current evidence of exploitation exists.