A critical security vulnerability has been identified in HIKVISION 's applyCT component , which is part of the HikCentral Integrated Security Management platform . This vulnerability allows attackers to execute arbitrary code remotely, without requiring authentication.
See also: Hackers abuse Vercel v0 for phishing attacks

It has been registered as CVE-2025-34067 and has been assigned the maximum CVSS score of 10.0. The cause of the vulnerability is the platform's use of a vulnerable version of the Fastjson , exposing millions of surveillance devices worldwide to potential compromise.
The attack exploits the /bic/ssoService/v1/applyCT access point via malicious JSON payloads processed by the Fastjson library. Attackers can craft specially crafted JSON requests that trigger Fastjson's auto-type feature, allowing the loading of arbitrary Java classes.
The attack mechanism is based on manipulating the JdbcRowSetImplto create connections to untrusted LDAP servers, effectively bypassing security measures.
Exploiting requires sending a POST request with Content-Type: application/json to the vulnerable access point. By appropriately modifying the datasource parameter to point to a malicious LDAP server, attackers can achieve remote code execution on the underlying system.
See also: Microsoft Defender now blocks email bombing attacks
This is a classic example of the CWE-502: Deserialization of Untrusted Data combined with CWE-917: Expression Language Injection, where insufficient input validation allows unauthorized class loading and code execution.

The vulnerability affects the HikCentral platform, which was previously known as the “Integrated Security Management Platform” and operates as a comprehensive security management solution, widely used in the public, commercial and industrial sectors.
The widespread adoption of the platform makes the vulnerability particularly concerning, as it offers centralized control of multiple security devices and surveillance systems.
Potential consequences include unauthorized access to sensitive surveillance data, interference with security systems, and possible lateral movement within the network infrastructure.
Organizations using the affected HIKVISION applyCT systems are at risk of data breaches, service , and broader breaches of their overall security infrastructure.
See also: Most Ransomware attacks on organizations are the result of vulnerabilities
The vulnerability is unauthenticated, meaning that attackers can exploit it without the need for valid credentials, which significantly reduces the level of difficulty for malicious actors. Due to this specificity, the vulnerability has been classified as known-and-exploited, which indicates that it is actively exploited in practice.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: cybersecuritynews
