← Back to CVE List
Vulnerability Intelligence Report
Hikvision Integrated Security Management Platform Remote Command Execution via applyCT Fastjson

CVE-2025-34067

x_known-exploited-vulnerability

An unauthenticated remote command execution vulnerability exists in the applyCT component of the Hikvision Integrated Security Management Platform due to the use of a vulnerable version of the Fastjson library. The endpoint /bic/ssoService/v1/applyCT deserializes untrusted user input, allowing an attacker to trigger Fastjson's auto-type feature to load arbitrary Java classes. By referencing a malicious class via an LDAP URL, an attacker can achieve remote code execution on the underlying system. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-05 UTC.

Deserialization No Active Exploit Signals
CVSS Base Score
10.0
CRITICAL
EPSS Probability:18.67%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-502 ↗CWE-502 Deserialization of Untrusted Data

Affected Products & Versions

Vendor Product Affected Versions
Hikvision Integrated Security Management Platform 0 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
18.666%
Vulnerability Class
Deserialization

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityVulnCheck · Bug Bounty Provider · USA
Reserved2025-04-15T19:15:22
Published2025-07-02T13:44:21
Last Updated2026-07-14T22:25:42

LINK COPIED TO CLIPBOARD