CVE-2025-39245

MEDIUM

HikCentral Master Lite - Command Injection

Title source: llm
STIX 2.1

Description

There is a CSV Injection Vulnerability in some HikCentral Master Lite versions. This could allow an attacker to inject executable commands via malicious CSV data.

Scores

CVSS v3 4.7
EPSS 0.0003
EPSS Percentile 8.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-1236
Status published
Products (1)
Hikvision/HikCentral Master Lite Versions between V2.2.1 and V2.3.2
Published Aug 29, 2025
Tracked Since Feb 18, 2026