Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-34067


An unauthenticated remote command execution vulnerability exists in the applyCT component of the Hikvision Integrated Security Management Platform due to the use of a vulnerable version of the Fastjson library. The endpoint /bic/ssoService/v1/applyCT deserializes untrusted user input, allowing an attacker to trigger Fastjson's auto-type feature to load arbitrary Java classes. By referencing a malicious class via an LDAP URL, an attacker can achieve remote code execution on the underlying system.


Published

2025-07-02T14:15:24.250

Last Modified

2025-07-07T15:15:26.333

Status

Awaiting Analysis

Source

[email protected]

Severity

-

Weaknesses
  • Type: Secondary
    CWE-502
    CWE-917

Affected Vendors & Products

-


References