Remote Command Execution Vulnerability in Hikvision CSMP iSecure Center
CVE-2024-58274

8.3HIGH

Key Information:

Vendor

Hikvision

Vendor
CVE Published:
22 October 2025

What is CVE-2024-58274?

An identified vulnerability in Hikvision's Comprehensive Security Management Platform, specifically within the iSecure Center application, permits remote command execution due to improper handling of JSON data in the API. This flaw allows attackers to inject and execute commands within the installation detection process, posing significant security risks. The vulnerability has been actively exploited in the wild, highlighting the urgency for users to address this security issue by applying appropriate patches and safeguards.

Affected Version(s)

CSMP iSecure Center 0 <= 2024-08-01

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.