Back to Database
Status published
Medium
CVE-2025-12063
An insecure direct object reference allowed a non-admin user to...
Vulnerability Description
An insecure direct object reference allowed a non-admin user to modify or remove certain data objects without having the appropriate permissions.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-12063
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Seth Fogie
More from Axis Communications AB
View All →CVE-2025-9524
The VAPIX API port.cgi did not have sufficient input validation,...
Medium
4.3
CVE-2025-9055
The VAPIX Edge storage API that allowed a privilege escalation,...
Medium
6.4
CVE-2025-8998
It was possible to upload files with a specific name...
Low
3.1
CVE-2025-8108
An ACAP configuration file has improper permissions and lacks input...
Medium
6.7
CVE-2025-7622
During an internal security assessment, a Server-Side Request Forgery (SSRF)...
Medium
5.1
Affected Vendor
Axis Communications AB
View all reports →Affected Software
AXIS Camera Station Pro
Vulnerable Versions:
6
Timeline
Official Publish:
February 10th, 2026
Last Modified:
February 10th, 2026
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N