CVE-2024-47485: Hikvision Hikcentral Master

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

There is a CSV injection vulnerability in some HikCentral Master Lite versions. If exploited, an attacker could build malicious data to generate executable commands in the CSV file.

Affected products

  • Hikvision Hikcentral Master: from 2.0.0, before 2.3.0 (fixed in 2.3.0)

Published 2024-10-18. Last modified 2026-06-17.