CVE-2025-34067
EXPLOITEDHikvision Integrated Security Management Platform - RCE
Title source: llmDescription
An unauthenticated remote command execution vulnerability exists in the applyCT component of the Hikvision Integrated Security Management Platform due to the use of a vulnerable version of the Fastjson library. The endpoint /bic/ssoService/v1/applyCT deserializes untrusted user input, allowing an attacker to trigger Fastjson's auto-type feature to load arbitrary Java classes. By referencing a malicious class via an LDAP URL, an attacker can achieve remote code execution on the underlying system. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-05 UTC.
References (3)
Scores
EPSS
0.0266
EPSS Percentile
85.6%
Exploitation Intel
VulnCheck KEV
2025-07-02
Classification
CWE
CWE-502
Status
draft
Timeline
Published
Jul 02, 2025
Tracked Since
Feb 18, 2026