nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-28815 CVE-2023-28815
CRITICAL
Record summary
CVE-2023-28815 has a selected CVSS score of 9.8 (critical).
Description
Some versions of Hikvision's iSecure Center Product contain insufficient parameter validation, resulting in a command injection vulnerability. Attackers may exploit this to gain platform privileges and execute arbitrary commands on the system.iSecure Center is software released for China's domestic market only, with no overseas release.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 17, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
iSecure CenterBrowse Hikvision / iSecure Center | CVE List | V1.0.0 - V1.7.0 | affected |
References
2hikvision.com
https://www.hikvision.com/cn/support/CybersecurityCenter/SecurityNotices/2023-04