CVE-2025-0926
📋 TL;DR
A non-admin user can delete critical system files by exploiting a file deletion redirection vulnerability during video recording in Axis Camera Station Pro. This causes a boot loop, rendering the system unusable. All systems running vulnerable versions of Axis Camera Station Pro are affected.
💻 Affected Systems
- Axis Camera Station Pro
📦 What is this software?
⚠️ Risk & Real-World Impact
Worst Case
Complete system failure with boot loop requiring physical intervention and potential data loss from critical file deletion.
Likely Case
Service disruption requiring system restoration from backup or reinstallation.
If Mitigated
Limited impact with proper access controls and monitoring preventing unauthorized file deletion.
🎯 Exploit Status
Requires authenticated non-admin access and knowledge of file redirection techniques during video recording operations.
🛠️ Fix & Mitigation
✅ Official Fix
Patch Version: Refer to Axis security advisory for specific patched version
Vendor Advisory: https://www.axis.com/dam/public/9d/fe/3f/cve-2025-0926pdf-en-US-479105.pdf
Restart Required: Yes
Instructions:
1. Download patched version from Axis support portal. 2. Backup current configuration. 3. Install update following Axis documentation. 4. Restart system. 5. Verify functionality.
🔧 Temporary Workarounds
Restrict user permissions
windowsLimit non-admin user access to video recording and file management functions
Implement file system monitoring
allMonitor for unauthorized file deletion attempts on critical system directories
🧯 If You Can't Patch
- Implement strict access controls to limit non-admin user capabilities
- Deploy file integrity monitoring on critical system directories
🔍 How to Verify
Check if Vulnerable:
Check Axis Camera Station Pro version against advisory. Verify if non-admin users have video recording access.
Check Version:
Check version in Axis Camera Station Pro administration interface or installation directory
Verify Fix Applied:
Confirm installation of patched version from Axis advisory. Test that non-admin users cannot delete system files during recording.
📡 Detection & Monitoring
Log Indicators:
- Unauthorized file deletion events in system logs
- Failed boot attempts
- Video recording service errors
Network Indicators:
- Unusual file deletion requests from non-admin accounts
SIEM Query:
EventID:4663 OR EventID:4656 WHERE ObjectName contains 'system32' OR 'program files' AND SubjectUserName not contains 'admin'