Showing 1 vulnerability on this page for Integrated Security Management Platform

Signals CISA KEV Ransomware Nuclei
Hikvision vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Hikvision Integrated Security Management Platform Remote Command Execution via applyCT Fastjson

An unauthenticated remote command execution vulnerability exists in the applyCT component of the Hikvision Integrated Security Management Platform due to the use of a vulnerable version of the Fastjson library. The endpoint /bic/ssoService/v1/applyCT deserializes untrusted user input, allowing an attacker to trigger Fastjson's auto-type feature to load arbitrary Java classes. By referencing a malicious class via an LDAP URL, an attacker can achieve remote code execution on the underlying system.

CWE-502Jul 2, 2025
CVSS10.0v4.0EPSS20.5%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX