Command Injection Vulnerability in Hikvision's iSecure Center Software
CVE-2023-28815

9.8CRITICAL

Key Information:

Vendor

Hikvision

Vendor
CVE Published:
17 October 2025

What is CVE-2023-28815?

A command injection vulnerability exists in Hikvision's iSecure Center software due to insufficient parameter validation. This flaw allows attackers to exploit the system, potentially gaining unauthorized platform privileges and executing arbitrary commands. It is important to note that this product is specifically designed for the domestic market in China, with no international release. Vigilance is required to prevent unauthorized access and ensure system integrity.

Affected Version(s)

iSecure Center V1.0.0 - V1.7.0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

hsrc
.
CVE-2023-28815 : Command Injection Vulnerability in Hikvision's iSecure Center Software