CVE-2025-34067

EXPLOITED

Hikvision Integrated Security Management Platform - RCE

Title source: llm

Description

An unauthenticated remote command execution vulnerability exists in the applyCT component of the Hikvision Integrated Security Management Platform due to the use of a vulnerable version of the Fastjson library. The endpoint /bic/ssoService/v1/applyCT deserializes untrusted user input, allowing an attacker to trigger Fastjson's auto-type feature to load arbitrary Java classes. By referencing a malicious class via an LDAP URL, an attacker can achieve remote code execution on the underlying system. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-05 UTC.

Scores

EPSS 0.0266
EPSS Percentile 85.6%

Exploitation Intel

VulnCheck KEV 2025-07-02

Classification

CWE
CWE-502
Status draft

Timeline

Published Jul 02, 2025
Tracked Since Feb 18, 2026