CVE-2024-58274: Hikvision Csmp Isecure Center

High severity, CVSS 8.3. EPSS: 19.1% chance of exploitation in the next 30 days.

Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2024-08-01 allows execution of a command within $( ) in /center/api/installation/detection JSON data, as exploited in the wild in 2024 and 2025.

Affected products

  • Hikvision Csmp Isecure Center: up to and including 2024-08-01

Published 2025-10-22. Last modified 2026-10-02.