CVE-2024-6476: Axis Communications Ab Axis Camera Station
Medium severity, CVSS 4.2. EPSS: 0.1% chance of exploitation in the next 30 days.
Gee-netics, member of the AXIS Camera Station Pro Bug Bounty Program has found that it is possible for a non-admin user to gain system privileges by redirecting a file deletion upon service restart. Axis has released patched versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.
Affected products
- Axis Communications Ab Axis Camera Station: before 5.57.33556 (fixed in 5.57.33556)
- Axis Communications Ab Axis Camera Station Pro: before 6.4 (fixed in 6.4)
Published 2024-11-26. Last modified 2026-06-17.