Hikvision’s Security Response Center (HSRC) has issued HSRC-202508-01 to disclose three critical security flaws in its HikCentral lineup.
The vulnerabilities—assigned CVE-2025-39245 through CVE-2025-39247—span from CSV injection to access control bypass, affecting multiple HikCentral editions.
Customers are urged to update to the latest patched versions immediately to prevent potential exploitation.
Detailed Vulnerability Overview
HSRC’s initial advisory, released on August 28, 2025, describes:
- CSV Injection in HikCentral Master Lite (CVE-2025-39245)
Versions V2.2.1 through V2.3.2 allow maliciously crafted CSV files to embed executable commands. When such CSVs are imported, an attacker could execute arbitrary commands on the host. Scored 4.7 (CVSS 3.1: AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:L), this vulnerability requires user interaction but can compromise system availability if leveraged. - Unquoted Service Path in HikCentral FocSign (CVE-2025-39246)
Versions V1.4.0 through V2.2.0 fail to enclose service executable paths in quotation marks. An authenticated local user could exploit this to escalate privileges by inserting a malicious binary in an unquoted segment of the service path. The base score is 5.3 (CVSS 3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N). - Access Control Bypass in HikCentral Professional (CVE-2025-39247)
Versions V2.3.1 through V2.6.2 contain insufficient access checks, enabling unauthenticated users to gain administrator privileges remotely. This high-impact flaw carries a CVSS 3.1 score of 8.6 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N), indicating severe potential for unauthorized control of critical surveillance systems.
Affected Versions and Remediation Table
| Product | CVE ID | Affected Versions | Fixed Version(s) |
|---|---|---|---|
| HikCentral Master Lite | CVE-2025-39245 | V2.2.1 – V2.3.2 | V2.4.0 |
| HikCentral FocSign | CVE-2025-39246 | V1.4.0 – V2.2.0 | V2.3.0 (Download) |
| HikCentral Professional | CVE-2025-39247 | V2.3.1 – V2.6.2 | V2.6.3 (Download) or V3.0.1 (Download) |
To obtain patched releases, users should contact their local technical support team via Hikvision’s support portal and reference the HSRC advisory number.
Hikvision extends its gratitude to the researchers who reported these issues: Yousef Alfuhaid, Nader Alharbi, Eduardo Bido, and Dr. Matthias Lutter.
Find this Story Interesting! Follow us on Google News , LinkedIn and X to Get More Instant Updates