{"id":5131,"date":"2025-07-05T10:04:05","date_gmt":"2025-07-05T10:04:05","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/07\/05\/critical-hikvision-applyct-vulnerability-exposes-devices-to-code-execution-attacks\/"},"modified":"2025-07-05T10:04:05","modified_gmt":"2025-07-05T10:04:05","slug":"critical-hikvision-applyct-vulnerability-exposes-devices-to-code-execution-attacks","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/07\/05\/critical-hikvision-applyct-vulnerability-exposes-devices-to-code-execution-attacks\/","title":{"rendered":"Critical HIKVISION applyCT Vulnerability Exposes Devices to Code Execution Attacks"},"content":{"rendered":"<p>    Critical HIKVISION applyCT Vulnerability Exposes Devices to Code Execution Attacks<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A critical security vulnerability has been discovered in HIKVISION\u2019s applyCT component, part of the HikCentral Integrated Security Management Platform, that allows attackers to execute arbitrary code remotely without authentication.\u00a0<\/p>\n<p>Assigned <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-34067\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">CVE-2025-34067<\/a> with a maximum CVSS score of 10.0, this vulnerability stems from the platform\u2019s use of a vulnerable version of the Fastjson library, exposing millions of surveillance devices worldwide to potential compromise.<\/p>\n<pre class=\"wp-block-preformatted\"><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-vivid-cyan-blue-color\"><strong>Key Takeaways<br><\/strong><\/mark>1. CVE-2025-34067 (CVSS 10.0) in HIKVISION applyCT allows unauthenticated remote code execution.<br>2. Exploits Fastjson library via malicious JSON to \/bic\/ssoService\/v1\/applyCT endpoint using LDAP connections.<br>3. Affects HikCentral surveillance platforms across government, commercial, and industrial sectors globally.<br>4. Assess deployments immediately, restrict network access, and contact HIKVISION for patches - actively exploited.<\/pre>\n<h2 class=\"wp-block-heading\"><strong>Critical Fastjson Deserialization Flaw<\/strong><\/h2>\n<p>The vulnerability exploits the \/bic\/ssoService\/v1\/applyCT endpoint through malicious <a href=\"https:\/\/cybersecuritynews.com\/python-json-logger-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">JSON payloads<\/a> processed by the Fastjson library.\u00a0<\/p>\n<p>Attackers can craft specific JSON requests that trigger Fastjson\u2019s auto-type feature, enabling the loading of arbitrary Java classes.\u00a0<\/p>\n<p>The attack mechanism involves manipulating the JdbcRowSetImpl class to establish connections with untrusted LDAP servers, effectively bypassing security controls.<\/p>\n<p>The exploit requires sending a POST request with Content-Type: application\/json to the vulnerable endpoint. By manipulating the datasource parameter to point to a malicious LDAP server, attackers can achieve remote code execution on the underlying system.<\/p>\n<p>This represents a classic case of CWE-502 Deserialization of Untrusted Data combined with CWE-917 Expression Language Injection, where insufficient <a href=\"https:\/\/cybersecuritynews.com\/notepad-input-validation-flaw\/\" target=\"_blank\" rel=\"noreferrer noopener\">input validation<\/a> allows unauthorized class loading and code execution.<\/p>\n<p>The vulnerability affects the HikCentral platform, formerly known as the \u201cIntegrated Security Management Platform,\u201d which serves as a comprehensive security management solution widely deployed across government, commercial, and industrial sectors.\u00a0<\/p>\n<p>The platform\u2019s extensive adoption makes this vulnerability particularly concerning, as it provides centralized control over multiple security devices and surveillance systems.<\/p>\n<p>Potential consequences include unauthorized access to sensitive surveillance data, manipulation of security systems, and the possibility of lateral movement within network infrastructure.\u00a0<\/p>\n<p>Organizations using affected HIKVISION applyCT systems face risks of data breaches, service disruptions, and potential compromise of their entire security infrastructure.<\/p>\n<p>The vulnerability\u2019s unauthenticated nature means attackers can exploit it without requiring valid credentials, significantly lowering the barrier to entry for malicious actors.\u00a0<\/p>\n<p>This has led to its classification as a known-exploited-vulnerability, indicating active exploitation in the wild.<\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<tbody>\n<tr>\n<td><strong>Risk Factors<\/strong><\/td>\n<td><strong>Details<\/strong><\/td>\n<\/tr>\n<tr>\n<td>Affected Products<\/td>\n<td>\u2013 HIKVISION HikCentral (formerly \u201cIntegrated Security Management Platform\u201d)- applyCT component- Versions using vulnerable Fastjson library<\/td>\n<\/tr>\n<tr>\n<td>Impact<\/td>\n<td>Remote Code Execution (RCE)<\/td>\n<\/tr>\n<tr>\n<td>Exploit Prerequisites<\/td>\n<td>\u2013 Network access to \/bic\/ssoService\/v1\/applyCT endpoint- Ability to send HTTP POST requests- No authentication required- Access to malicious LDAP server<\/td>\n<\/tr>\n<tr>\n<td>CVSS Score<\/td>\n<td>10.0 (Critical)<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<h2 class=\"wp-block-heading\"><strong>Mitigations<\/strong><\/h2>\n<p>Organizations should immediately assess their HIKVISION applyCT deployments and implement network segmentation to limit exposure.\u00a0<\/p>\n<p>Monitoring for unusual network traffic to the \/bic\/ssoService\/v1\/applyCT endpoint can help detect attempts at exploitation.\u00a0<\/p>\n<p>While specific patches have not been detailed in current advisories, users should contact HIKVISION support for immediate remediation guidance and consider temporarily restricting access to the vulnerable endpoint until patches are available.<\/p>\n<p>Security teams should also implement additional monitoring for LDAP connection attempts from their HIKVISION systems and consider deploying network-based <a href=\"https:\/\/cybersecuritynews.com\/network-intrusion-detection-systems-in-soc\/\" target=\"_blank\" rel=\"noreferrer noopener\">intrusion detection<\/a> systems to identify potential exploitation attempts targeting this critical vulnerability.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\">Investigate live malware behavior, trace every step of an attack, and make faster, smarter security decisions -&gt; <a href=\"https:\/\/any.run\/demo?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=braodo_stealer&amp;utm_content=demo_1&amp;utm_term=250625\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><strong>Try ANY.RUN now<\/strong><\/a>\u00a0<\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/hikvision-applyct-vulnerability\/\">Critical HIKVISION applyCT Vulnerability Exposes Devices to Code Execution Attacks<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Kaaviya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/hikvision-applyct-vulnerability\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Critical HIKVISION applyCT Vulnerability Exposes Devices to Code Execution Attacks A critical security vulnerability has been discovered in HIKVISION\u2019s applyCT component, part of the HikCentral Integrated Security Management Platform, that allows attackers to execute arbitrary code remotely without authentication.\u00a0 Assigned CVE-2025-34067 with a maximum CVSS score of 10.0, this vulnerability stems from the platform\u2019s use [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[677,129,63,131],"tags":[130],"class_list":["post-5131","post","type-post","status-publish","format-standard","hentry","category-cyber-attack-article","category-cyber-security","category-cyber-security-news","category-vulnerability","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5131"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=5131"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5131\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=5131"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=5131"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=5131"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}