Multiple Hikvision Flaws Allow Attackers to Execute Arbitrary Commands

Hikvision’s Security Response Center (HSRC) has issued HSRC-202508-01 to disclose three critical security flaws in its HikCentral lineup.

The vulnerabilities—assigned CVE-2025-39245 through CVE-2025-39247—span from CSV injection to access control bypass, affecting multiple HikCentral editions.

Customers are urged to update to the latest patched versions immediately to prevent potential exploitation.

Detailed Vulnerability Overview

HSRC’s initial advisory, released on August 28, 2025, describes:

  1. CSV Injection in HikCentral Master Lite (CVE-2025-39245)
    Versions V2.2.1 through V2.3.2 allow maliciously crafted CSV files to embed executable commands. When such CSVs are imported, an attacker could execute arbitrary commands on the host. Scored 4.7 (CVSS 3.1: AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:L), this vulnerability requires user interaction but can compromise system availability if leveraged.
  2. Unquoted Service Path in HikCentral FocSign (CVE-2025-39246)
    Versions V1.4.0 through V2.2.0 fail to enclose service executable paths in quotation marks. An authenticated local user could exploit this to escalate privileges by inserting a malicious binary in an unquoted segment of the service path. The base score is 5.3 (CVSS 3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).
  3. Access Control Bypass in HikCentral Professional (CVE-2025-39247)
    Versions V2.3.1 through V2.6.2 contain insufficient access checks, enabling unauthenticated users to gain administrator privileges remotely. This high-impact flaw carries a CVSS 3.1 score of 8.6 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N), indicating severe potential for unauthorized control of critical surveillance systems.

Affected Versions and Remediation Table

ProductCVE IDAffected VersionsFixed Version(s)
HikCentral Master LiteCVE-2025-39245V2.2.1 – V2.3.2V2.4.0
HikCentral FocSignCVE-2025-39246V1.4.0 – V2.2.0V2.3.0 (Download)
HikCentral ProfessionalCVE-2025-39247V2.3.1 – V2.6.2V2.6.3 (Download)
or V3.0.1 (Download)

To obtain patched releases, users should contact their local technical support team via Hikvision’s support portal and reference the HSRC advisory number.

Hikvision extends its gratitude to the researchers who reported these issues: Yousef Alfuhaid, Nader Alharbi, Eduardo Bido, and Dr. Matthias Lutter.

Find this Story Interesting! Follow us on Google News , LinkedIn and X to Get More Instant Updates

AnuPriya
AnuPriya
Any Priya is a cybersecurity reporter at Cyber Press, specializing in cyber attacks, dark web monitoring, data breaches, vulnerabilities, and malware. She delivers in-depth analysis on emerging threats and digital security trends.

Trending News

Related Stories