External risk intelligence

Axxon One VMS Unmaintained Components Code Execution Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2025-10220

Axxon One is a Video Management System (VMS) platform. These systems are commonly deployed as internet-facing services to allow remote access to video feeds and management interfaces from external networks, making the web-based or API-based management surface frequently reachable from the public internet.

Axxonsoft Axxon One

2.0.0 to 2.0.4

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability in Axxon One video management software that arises from the use of unmaintained third-party components. The issue allows remote attackers to potentially execute arbitrary code or bypass security controls by exploiting these vulnerable components. Understanding and addressing this risk is important for maintaining the security posture of affected systems.

  • Unmaintained software components pose a risk.
  • Enables remote code execution.
  • Confirm relevance and exposure of affected systems.

Attack Path

How an attacker could exploit the issue

An attacker could exploit vulnerable third-party packages within AxxonSoft Axxon One VMS to gain unauthorized access. This could happen remotely, without needing any prior authentication or specific user interaction, potentially leading to severe security breaches.

  • No authentication required to reach.
  • Vulnerable third-party packages are triggered.
  • Remote arbitrary code execution or bypass.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, a remote attacker could exploit unmaintained third-party components within Axxon One VMS, potentially leading to arbitrary code execution or bypassing security features. This could affect the integrity and availability of the video management system.

  • System integrity and availability.
  • Remote code execution via vulnerable components.
  • Unauthorized system access or control.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability resides within the third-party components used by Axxon One VMS. Therefore, the Application owner is primarily responsible for addressing this issue, in coordination with the Infrastructure and Security teams. The first step is to identify all instances of Axxon One VMS within the environment, confirm their reachability and business criticality, and then engage the accountable owner to plan remediation.

  • Application owners must lead remediation efforts.
  • Verify all Axxon One VMS deployments.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Axxon One VMS?

Axxon One is a Video Management System (VMS) platform designed to handle video surveillance infrastructure. Users typically rely on this software to aggregate, record, and manage video feeds from various security cameras. Because it serves as a central hub for monitoring and security operations, it is often installed on Windows-based servers where it facilitates both local management and remote access to live or recorded video streams across an organization's network.

How does CVE-2025-10220 work?

This vulnerability, classified as CWE-1104, involves the use of unmaintained third-party components within the software. Because these included packages are no longer updated or supported by their original creators, they may contain known security flaws. By targeting these specific dependencies—such as Google.Protobuf or others bundled with the system—an attacker can leverage those pre-existing weaknesses to run unauthorized code or bypass the security controls that protect the main application.

Does this issue require user interaction to trigger?

No, this vulnerability does not require any specific user interaction or prior authentication to be exploited. An attacker can trigger the flaw remotely by interacting with the application's network-facing services. Importantly, the bug is rooted in the presence of the outdated third-party code; simply having the vulnerable version of the Axxon One software running makes the system susceptible, regardless of whether a specific administrative user is logged in or interacting with the interface.

How do I know if my systems are at risk?

You should assess your exposure by identifying where Axxon One is deployed within your environment. According to Halo Surface Signal, these systems are commonly configured as internet-facing services to enable remote access to video feeds and management interfaces. If your instance is reachable from the public internet, it sits in a higher-risk category. Teams should prioritize mapping every instance of the software to determine if they are exposed to external network traffic.

What is the first step to address this CVE?

The initial action for an organization is to locate all instances of Axxon One VMS running versions 2.0.0 through 2.0.4. Once an inventory is established, application owners should coordinate with security teams to verify how these systems are connected to the network. Since the fix requires managing third-party dependencies within the software, your goal at this stage is to confirm the business criticality of each deployment and prepare a plan for remediation in collaboration with your IT staff.

References