NONE · 0

CVE-2025-34067

An unauthenticated remote command execution vulnerability exists in the applyCT component of the Hikvision Integrated Security Management Platform due to the use of a vulnerable version of the Fastjso...

Vulnerability Description

An unauthenticated remote command execution vulnerability exists in the applyCT component of the Hikvision Integrated Security Management Platform due to the use of a vulnerable version of the Fastjson library. The endpoint /bic/ssoService/v1/applyCT deserializes untrusted user input, allowing an attacker to trigger Fastjson's auto-type feature to load arbitrary Java classes. By referencing a malicious class via an LDAP URL, an attacker can achieve remote code execution on the underlying system. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-05 UTC.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-34067?

CVE-2025-34067 is a documented vulnerability. An unauthenticated remote command execution vulnerability exists in the applyCT component of the Hikvision Integrated Security Management Platform due to the use of a vulnerable version of the Fastjso...

How severe is CVE-2025-34067?

CVSS scoring is not yet available for CVE-2025-34067. Check NVD for updates.

Is there a patch for CVE-2025-34067?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.