PT-2025-29200 · Apache · Apache Http Server

·

CVE-2025-30023

·

Published

2025-07-11

·

Updated

2026-01-23

CVSS v3.1

9.0

Critical

VectorAV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Axis Video Management Software (affected versions not specified)
Description The communication protocol used between the client and server has a flaw that could allow an authenticated user to perform a remote code execution attack. The issue involves improper serialized data handling between the client and server, enabling attackers to execute code without user interaction, which is suitable for lateral movement within a network.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-11338
CVE-2025-30023

Affected Products

Apache Http Server