Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Socgholish malware spreads through AD tools. Provides access to Lockbit, Evil Corp and more

SpaceX is building a Starbase water pipeline, but access comes with several conditions

Openai’s GPT-5 is here | TechCrunch

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » The 6,500 axis server exposes the remote protocol. 4,000 people in the US are vulnerable to exploitation
Identity

The 6,500 axis server exposes the remote protocol. 4,000 people in the US are vulnerable to exploitation

userBy userAugust 7, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

August 7, 2025Ravi LakshmananVulnerability/Threat Intelligence

Cybersecurity researchers have disclosed multiple security flaws in video surveillance products from Axis Communications, which, if successfully exploited, can now take over the attack.

“This attack will have pre-certified remote code execution in Axis Device Manager, servers used to configure and manage camera fleets, and Axis camera stations for client software used to view camera feeds.”

“In addition, using Internet scanning of exposed axes, attackers can enumerate vulnerable servers and clients and carry out granular, highly targeted attacks.”

Cybersecurity

The list of identified defects is as follows:

CVE-2025-30023 (CVSS score: 9.0) – Fault in the communication protocol used between client and server. This could lead to authenticated users performing remote station execution attacks (camera manager 5.58, and device manager 5.32, and device manager 5.32) and could be used with the client score used for CVE-2025-30024 (CVSS score: 6.8). Performs intermediate (AITM) attack (fixed with device manager 5.32) CVE-2025-30025 (CVSS score: 4.8) – Defective Axis Camera Station Server Fault (fixed with Camera Station Pro 6.9 and Camera Station 5.58)

The successful exploitation of the aforementioned vulnerability allows an attacker to assume the AITM location between the camera station and its clients, effectively modifying requests/responses and performing any action on either the server or client system. There is no evidence that the problem was exploited in the wild.

Identity Security Risk Assessment

Claroty said it found over 6,500 servers that expose their own axis.

“A successful exploit gives the attacker system-level access on the internal network and the ability to control each camera in a particular deployment,” Moshe said. “The feed can be hijacked, monitored, and/or shut down. Attackers can take advantage of these security issues to bypass authentication to the camera and obtain remote code execution before authentication on the device.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleI’m teaching you about cloud defense in 2025
Next Article Microsoft discloses defects in Exchange Server that allow silent cloud access in hybrid setups
user
  • Website

Related Posts

Socgholish malware spreads through AD tools. Provides access to Lockbit, Evil Corp and more

August 7, 2025

Malicious GO, NPM package provides cross-platform malware and triggers remote data wipes

August 7, 2025

Microsoft discloses defects in Exchange Server that allow silent cloud access in hybrid setups

August 7, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Socgholish malware spreads through AD tools. Provides access to Lockbit, Evil Corp and more

SpaceX is building a Starbase water pipeline, but access comes with several conditions

Openai’s GPT-5 is here | TechCrunch

Data breaches at French telecom giant Bouigs impact millions of customers

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Google’s Genie 3: The Dawn of General AI?

FySelf, PODs, TwinH: Revolutionizing Digital Identity & Government Data Control

Beyond Zuckerberg’s Metaverse: TwinH Powers Digital Government with Berners-Lee’s New Internet Vision

The TwinH Advantage: Unlocking New Potential in Digital Government Strategies

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.