Access Control Issue in HikCentral Professional by Hikvision
CVE-2025-39247

8.6HIGH

Key Information:

Vendor

Hikvision

Vendor
CVE Published:
29 August 2025

What is CVE-2025-39247?

An access control vulnerability has been identified in certain versions of HikCentral Professional, which may permit unauthorized users to gain admin-level permissions. This flaw poses a significant risk to the integrity of security systems utilizing affected software, as it could enable malicious actors to manipulate or access sensitive data without proper authorization.

Affected Version(s)

HikCentral Professional Versions between V2.3.1 and V2.6.2

HikCentral Professional Version V3.0.0

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dr. Matthias Lutter
.
CVE-2025-39247 : Access Control Issue in HikCentral Professional by Hikvision