HomeSecurityCritical HIKVISION applyCT vulnerability exposes devices to attacks

Critical HIKVISION applyCT vulnerability exposes devices to attacks

A critical security vulnerability has been identified in HIKVISION 's applyCT component , which is part of the HikCentral Integrated Security Management platform . This vulnerability allows attackers to execute arbitrary code remotely, without requiring authentication.

See also: Hackers abuse Vercel v0 for phishing attacks

HIKVISION vulnerability

It has been registered as CVE-2025-34067 and has been assigned the maximum CVSS score of 10.0. The cause of the vulnerability is the platform's use of a vulnerable version of the Fastjson , exposing millions of surveillance devices worldwide to potential compromise.

The attack exploits the /bic/ssoService/v1/applyCT access point via malicious JSON payloads processed by the Fastjson library. Attackers can craft specially crafted JSON requests that trigger Fastjson's auto-type feature, allowing the loading of arbitrary Java classes.

The attack mechanism is based on manipulating the JdbcRowSetImplto create connections to untrusted LDAP servers, effectively bypassing security measures.

Exploiting requires sending a POST request with Content-Type: application/json to the vulnerable access point. By appropriately modifying the datasource parameter to point to a malicious LDAP server, attackers can achieve remote code execution on the underlying system.

See also: Microsoft Defender now blocks email bombing attacks

This is a classic example of the CWE-502: Deserialization of Untrusted Data combined with CWE-917: Expression Language Injection, where insufficient input validation allows unauthorized class loading and code execution.

Critical HIKVISION applyCT vulnerability exposes devices to attacks
Critical HIKVISION applyCT vulnerability exposes devices to attacks

The vulnerability affects the HikCentral platform, which was previously known as the “Integrated Security Management Platform” and operates as a comprehensive security management solution, widely used in the public, commercial and industrial sectors.

The widespread adoption of the platform makes the vulnerability particularly concerning, as it offers centralized control of multiple security devices and surveillance systems.

Potential consequences include unauthorized access to sensitive surveillance data, interference with security systems, and possible lateral movement within the network infrastructure.

Organizations using the affected HIKVISION applyCT systems are at risk of data breaches, service , and broader breaches of their overall security infrastructure.

See also: Most Ransomware attacks on organizations are the result of vulnerabilities

The vulnerability is unauthenticated, meaning that attackers can exploit it without the need for valid credentials, which significantly reduces the level of difficulty for malicious actors. Due to this specificity, the vulnerability has been classified as known-and-exploited, which indicates that it is actively exploited in practice.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Source: cybersecuritynews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS