CVE-2025-0926

5.9 MEDIUM

📋 TL;DR

A non-admin user can delete critical system files by exploiting a file deletion redirection vulnerability during video recording in Axis Camera Station Pro. This causes a boot loop, rendering the system unusable. All systems running vulnerable versions of Axis Camera Station Pro are affected.

💻 Affected Systems

Products:
  • Axis Camera Station Pro
Versions: Specific versions not provided in description - refer to Axis advisory
Operating Systems: Windows (based on typical Axis Camera Station deployment)
Default Config Vulnerable: ⚠️ Yes
Notes: Requires non-admin user access to the system. Video recording functionality must be accessible.

📦 What is this software?

⚠️ Risk & Real-World Impact

🔴

Worst Case

Complete system failure with boot loop requiring physical intervention and potential data loss from critical file deletion.

🟠

Likely Case

Service disruption requiring system restoration from backup or reinstallation.

🟢

If Mitigated

Limited impact with proper access controls and monitoring preventing unauthorized file deletion.

🌐 Internet-Facing: MEDIUM - Requires authenticated access but could be exploited if system is exposed to untrusted networks.
🏢 Internal Only: MEDIUM - Insider threat or compromised internal account could cause significant disruption.

🎯 Exploit Status

Public PoC: ✅ No
Weaponized: UNKNOWN
Unauthenticated Exploit: ✅ No
Complexity: MEDIUM

Requires authenticated non-admin access and knowledge of file redirection techniques during video recording operations.

🛠️ Fix & Mitigation

✅ Official Fix

Patch Version: Refer to Axis security advisory for specific patched version

Vendor Advisory: https://www.axis.com/dam/public/9d/fe/3f/cve-2025-0926pdf-en-US-479105.pdf

Restart Required: Yes

Instructions:

1. Download patched version from Axis support portal. 2. Backup current configuration. 3. Install update following Axis documentation. 4. Restart system. 5. Verify functionality.

🔧 Temporary Workarounds

Restrict user permissions

windows

Limit non-admin user access to video recording and file management functions

Implement file system monitoring

all

Monitor for unauthorized file deletion attempts on critical system directories

🧯 If You Can't Patch

  • Implement strict access controls to limit non-admin user capabilities
  • Deploy file integrity monitoring on critical system directories

🔍 How to Verify

Check if Vulnerable:

Check Axis Camera Station Pro version against advisory. Verify if non-admin users have video recording access.

Check Version:

Check version in Axis Camera Station Pro administration interface or installation directory

Verify Fix Applied:

Confirm installation of patched version from Axis advisory. Test that non-admin users cannot delete system files during recording.

📡 Detection & Monitoring

Log Indicators:

  • Unauthorized file deletion events in system logs
  • Failed boot attempts
  • Video recording service errors

Network Indicators:

  • Unusual file deletion requests from non-admin accounts

SIEM Query:

EventID:4663 OR EventID:4656 WHERE ObjectName contains 'system32' OR 'program files' AND SubjectUserName not contains 'admin'

🔗 References

📤 Share & Export