An insecure direct object reference allowed a non-admin user to modify or remove certain data objects without having the appropriate permissions.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 10 Feb 2026 06:30:00 +0000

Type Values Removed Values Added
Description An insecure direct object reference allowed a non-admin user to modify or remove certain data objects without having the appropriate permissions.
First Time appeared Axis Communications Ab
Axis Communications Ab axis Camera Station Pro
Weaknesses CWE-639
CPEs cpe:2.3:a:axis_communications_ab:axis_camera_station_pro:*:*:*:*:*:*:*:*
Vendors & Products Axis Communications Ab
Axis Communications Ab axis Camera Station Pro
References
Metrics cvssV3_1

{'score': 5.7, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Axis

Published:

Updated: 2026-02-10T05:52:35.732Z

Reserved: 2025-10-22T12:39:08.436Z

Link: CVE-2025-12063

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-02-10T07:16:12.553

Modified: 2026-02-10T07:16:12.553

Link: CVE-2025-12063

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-02-10T11:34:31Z

Weaknesses