Security Advisory

CVE-2025-34067

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-07-02 13:44:21
Last updated 2026-07-14 22:25:42
Assigner VulnCheck
CVSS score 10.0
State PUBLISHED

Description

An unauthenticated remote command execution vulnerability exists in the applyCT component of the Hikvision Integrated Security Management Platform due to the use of a vulnerable version of the Fastjson library. The endpoint /bic/ssoService/v1/applyCT deserializes untrusted user input, allowing an attacker to trigger Fastjson's auto-type feature to load arbitrary Java classes. By referencing a malicious class via an LDAP URL, an attacker can achieve remote code execution on the underlying system. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-05 UTC.