Authenticated Remote Command Execution in Hikvision Wireless Access Points
CVE-2025-39240
What is CVE-2025-39240?
Certain models of Hikvision Wireless Access Points are prone to a vulnerability that allows authenticated attackers to execute arbitrary commands remotely. This security flaw stems from inadequate input validation, enabling individuals with valid credentials to send specially crafted packets to the affected devices. Successful exploitation could lead to significant security breaches, allowing unauthorized operations on the device and potentially compromising the entire network.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
DS-3WAP521-SI V1.1.5400 build240814(E2254)and the versions prior to it
DS-3WAP522-SI V1.1.5402 build241014(E2254P02)and the versions prior to it
DS-3WAP621E-SI V1.1.5400 build240814(E2254)and the versions prior to it
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
