File Upload Vulnerability in Hikvision CSMP iSecure Center
CVE-2023-53691

8.3HIGH

Key Information:

Vendor

Hikvision

Vendor
CVE Published:
22 October 2025

What is CVE-2023-53691?

The Hikvision CSMP iSecure Center is vulnerable to a directory traversal issue that allows unauthorized file uploads via the /center/api/files endpoint. This vulnerability can be exploited to gain access to sensitive system areas, potentially leading to malicious file execution and data breaches. Users are encouraged to review their security settings and apply necessary updates to mitigate the risk associated with this exploit.

Affected Version(s)

CSMP iSecure Center 0 <= 2023-06-25

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.