CVE-2025-34067: Hikvision Integrated Security Management Platform

Critical severity, CVSS 10.0. EPSS: 22% chance of exploitation in the next 30 days.

An unauthenticated remote command execution vulnerability exists in the applyCT component of the Hikvision Integrated Security Management Platform due to the use of a vulnerable version of the Fastjson library. The endpoint /bic/ssoService/v1/applyCT deserializes untrusted user input, allowing an attacker to trigger Fastjson's auto-type feature to load arbitrary Java classes. By referencing a malicious class via an LDAP URL, an attacker can achieve remote code execution on the underlying system. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-05 UTC.

Affected products

  • Hikvision Integrated Security Management Platform: version 0 only

Published 2025-07-02. Last modified 2026-06-17.