CVE-2025-34067 is a critical unauthenticated remote command execution vulnerability affecting the applyCT component of the Hikvision Integrated Security Management Platform. It stems from the use of a vulnerable Fastjson library, allowing attackers to deserialize untrusted input via the /bic/ssoService/v1/applyCT endpoint. This enables arbitrary Java class loading and, consequently, remote code execution with a CVSS score of 10.0. Exploitation has been observed by the Shadowserver Foundation as of February 5, 2025, indicating active attacks, though public exploit code and community discussion are currently absent.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Hikvision | Integrated Security Management Platform | 0CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.