{"advisories":[{"id":"EUVD-2025-19719","source":"euvd","title":"An unauthenticated remote command execution vulnerability exists in the applyCT component of the Hikvision Integrated Security Management Platform due to the use of a vulnerable version of the Fastjson library. The endpoint /bic/ssoService/v1/applyCT deserializes untrusted user input, allowing an attacker to trigger Fastjson's auto-type feature to load arbitrary Java classes. By referencing a malicious class via an LDAP URL, an attacker can achieve remote code execution on the underlying system.","url":"https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-19719"}],"cve":"CVE-2025-34067","epss":{"score":0.18874},"mitre":{"cpes":["cpe:2.3:a:avaya:integrated_management:0:*:*:*:*:*:*:*"],"created":"2025-07-02T13:44:21.664000+00:00","description":"An unauthenticated remote command execution vulnerability exists in the applyCT component of the Hikvision Integrated Security Management Platform due to the use of a vulnerable version of the Fastjson library. The endpoint /bic/ssoService/v1/applyCT deserializes untrusted user input, allowing an attacker to trigger Fastjson's auto-type feature to load arbitrary Java classes. By referencing a malicious class via an LDAP URL, an attacker can achieve remote code execution on the underlying system. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-05 UTC.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{"score":10,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"}},"mitre_repo_path":"cves/2025/34xxx/CVE-2025-34067.json","references":["https://github.com/PeiQi0/PeiQi-WIKI-Book/blob/main/docs/wiki/iot/HIKVISION/HIKVISION%20%E7%BB%BC%E5%90%88%E5%AE%89%E9%98%B2%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0%20applyCT%20Fastjson%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md","https://s4e.io/tools/hikvision-applyct-remote-code-execution","https://vulncheck.com/advisories/hikvision-ismp-rce-applyct"],"title":"Hikvision Integrated Security Management Platform Remote Command Execution via applyCT Fastjson","updated":"2026-07-14T22:25:42.705000+00:00","vendors":["avaya","avaya$PRODUCT$integrated_management"],"weaknesses":["CWE-502"]},"nvd":{"cpes":[],"created":"2025-07-02T14:15:24.250000+00:00","description":"An unauthenticated remote command execution vulnerability exists in the applyCT component of the Hikvision Integrated Security Management Platform due to the use of a vulnerable version of the Fastjson library. The endpoint /bic/ssoService/v1/applyCT deserializes untrusted user input, allowing an attacker to trigger Fastjson's auto-type feature to load arbitrary Java classes. By referencing a malicious class via an LDAP URL, an attacker can achieve remote code execution on the underlying system. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-05 UTC.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{"score":10.0,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}},"nvd_repo_path":"2025/CVE-2025-34067.json","references":["https://github.com/PeiQi0/PeiQi-WIKI-Book/blob/main/docs/wiki/iot/HIKVISION/HIKVISION%20%E7%BB%BC%E5%90%88%E5%AE%89%E9%98%B2%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0%20applyCT%20Fastjson%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md","https://s4e.io/tools/hikvision-applyct-remote-code-execution","https://vulncheck.com/advisories/hikvision-ismp-rce-applyct"],"title":null,"updated":"2026-06-17T09:13:24.850000+00:00","vendors":[],"weaknesses":["CWE-502"]},"opencve":{"changes":[{"created":"2025-07-02T14:00:00+00:00","data":[{"details":{"new":"An unauthenticated remote command execution vulnerability exists in the applyCT component of the Hikvision Integrated Security Management Platform due to the use of a vulnerable version of the Fastjson library. The endpoint /bic/ssoService/v1/applyCT deserializes untrusted user input, allowing an attacker to trigger Fastjson's auto-type feature to load arbitrary Java classes. By referencing a malicious class via an LDAP URL, an attacker can achieve remote code execution on the underlying system.","old":null},"type":"description"},{"details":{"new":"Hikvision HikCentral (formerly \"Integrated Security Management Platform\") Remote Command Execution via applyCT Fastjson","old":null},"type":"title"},{"details":{"added":["CWE-502","CWE-917"],"removed":[]},"type":"weaknesses"},{"details":{"added":["https://github.com/PeiQi0/PeiQi-WIKI-Book/blob/main/docs/wiki/iot/HIKVISION/HIKVISION%20%E7%BB%BC%E5%90%88%E5%AE%89%E9%98%B2%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0%20applyCT%20Fastjson%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md","https://s4e.io/tools/hikvision-applyct-remote-code-execution","https://vulncheck.com/advisories/hikvision-hik-central-remote-command-execution"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV4_0":{"score":10,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"4d831ea1-ccf7-4f99-960e-fa79fa43072b"},{"created":"2025-07-02T21:15:00+00:00","data":[{"details":{"added":{"ssvc":{"options":{"Automatable":"no","Exploitation":"poc","Technical Impact":"partial"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"26622d24-2cc9-4952-879b-613f50152e69"},{"created":"2025-07-07T15:00:00+00:00","data":[{"details":{"new":"Hikvision Integrated Security Management Platform Remote Command Execution via applyCT Fastjson","old":"Hikvision HikCentral (formerly \"Integrated Security Management Platform\") Remote Command Execution via applyCT Fastjson"},"type":"title"},{"details":{"added":["https://vulncheck.com/advisories/hikvision-ismp-rce-applyct"],"removed":[]},"type":"references"}],"id":"15e97305-4a6e-4abe-9209-a9ed5cb5cfd2"},{"created":"2025-07-07T15:45:00+00:00","data":[{"details":{"added":[],"removed":["https://vulncheck.com/advisories/hikvision-hik-central-remote-command-execution"]},"type":"references"}],"id":"0d095551-76d1-42d8-b1c2-0597cbae3645"},{"created":"2025-07-16T13:45:00+00:00","data":[{"details":{"added":{},"removed":{},"updated":{"epss":{"new":{"score":0.00588},"old":{"score":0.00501}}}},"type":"metrics"}],"id":"64897231-162c-43bf-b84d-36671e2db600"},{"created":"2025-11-13T19:15:00+00:00","data":[{"details":{"new":"An unauthenticated remote command execution vulnerability exists in the applyCT component of the Hikvision Integrated Security Management Platform due to the use of a vulnerable version of the Fastjson library. The endpoint /bic/ssoService/v1/applyCT deserializes untrusted user input, allowing an attacker to trigger Fastjson's auto-type feature to load arbitrary Java classes. By referencing a malicious class via an LDAP URL, an attacker can achieve remote code execution on the underlying system. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-08 UTC.","old":"An unauthenticated remote command execution vulnerability exists in the applyCT component of the Hikvision Integrated Security Management Platform due to the use of a vulnerable version of the Fastjson library. The endpoint /bic/ssoService/v1/applyCT deserializes untrusted user input, allowing an attacker to trigger Fastjson's auto-type feature to load arbitrary Java classes. By referencing a malicious class via an LDAP URL, an attacker can achieve remote code execution on the underlying system."},"type":"description"}],"id":"514a0cb4-58a9-4984-b7ab-a6100360f910"},{"created":"2025-11-13T19:30:00+00:00","data":[{"details":{"added":[],"removed":["CWE-917"]},"type":"weaknesses"}],"id":"82c905eb-9faa-4081-9f9c-87f5d04b8286"},{"created":"2025-11-20T19:00:00+00:00","data":[{"details":{"new":"An unauthenticated remote command execution vulnerability exists in the applyCT component of the Hikvision Integrated Security Management Platform due to the use of a vulnerable version of the Fastjson library. The endpoint /bic/ssoService/v1/applyCT deserializes untrusted user input, allowing an attacker to trigger Fastjson's auto-type feature to load arbitrary Java classes. By referencing a malicious class via an LDAP URL, an attacker can achieve remote code execution on the underlying system. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-05 UTC.","old":"An unauthenticated remote command execution vulnerability exists in the applyCT component of the Hikvision Integrated Security Management Platform due to the use of a vulnerable version of the Fastjson library. The endpoint /bic/ssoService/v1/applyCT deserializes untrusted user input, allowing an attacker to trigger Fastjson's auto-type feature to load arbitrary Java classes. By referencing a malicious class via an LDAP URL, an attacker can achieve remote code execution on the underlying system. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-08 UTC."},"type":"description"}],"id":"1541b399-6e49-45d8-8408-93ffd7c56a01"},{"created":"2026-07-14T22:45:00+00:00","data":[{"details":["avaya","avaya$PRODUCT$integrated_management"],"type":"first_time"},{"details":{"added":["cpe:2.3:a:avaya:integrated_management:0:*:*:*:*:*:*:*"],"removed":[]},"type":"cpes"},{"details":{"added":["avaya","avaya$PRODUCT$integrated_management"],"removed":[]},"type":"vendors"}],"id":"286708eb-6298-4488-acef-caff0e420f1f"}],"cpes":{"data":["cpe:2.3:a:avaya:integrated_management:0:*:*:*:*:*:*:*"],"providers":["mitre"]},"created":{"data":"2025-07-02T13:44:21.664000+00:00","provider":"mitre"},"description":{"data":"An unauthenticated remote command execution vulnerability exists in the applyCT component of the Hikvision Integrated Security Management Platform due to the use of a vulnerable version of the Fastjson library. The endpoint /bic/ssoService/v1/applyCT deserializes untrusted user input, allowing an attacker to trigger Fastjson's auto-type feature to load arbitrary Java classes. By referencing a malicious class via an LDAP URL, an attacker can achieve remote code execution on the underlying system. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-05 UTC.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{},"provider":null},"cvssV4_0":{"data":{"score":10,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"},"provider":"mitre"},"epss":{"data":{"score":0.18874},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"no","Exploitation":"poc","Technical Impact":"partial"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://github.com/PeiQi0/PeiQi-WIKI-Book/blob/main/docs/wiki/iot/HIKVISION/HIKVISION%20%E7%BB%BC%E5%90%88%E5%AE%89%E9%98%B2%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0%20applyCT%20Fastjson%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md","https://s4e.io/tools/hikvision-applyct-remote-code-execution","https://vulncheck.com/advisories/hikvision-ismp-rce-applyct"],"providers":["mitre","nvd"]},"title":{"data":"Hikvision Integrated Security Management Platform Remote Command Execution via applyCT Fastjson","provider":"mitre"},"updated":{"data":"2026-07-14T22:25:42.705000+00:00","provider":"mitre"},"vendors":{"data":["avaya","avaya$PRODUCT$integrated_management"],"providers":["mitre"]},"weaknesses":{"data":["CWE-502"],"providers":["mitre","nvd"]}},"vulnrichment":{"cpes":[],"created":"2025-07-02T13:44:21.664000+00:00","description":"An unauthenticated remote command execution vulnerability exists in the applyCT component of the Hikvision Integrated Security Management Platform due to the use of a vulnerable version of the Fastjson library. The endpoint /bic/ssoService/v1/applyCT deserializes untrusted user input, allowing an attacker to trigger Fastjson's auto-type feature to load arbitrary Java classes. By referencing a malicious class via an LDAP URL, an attacker can achieve remote code execution on the underlying system. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-05 UTC.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"no","Exploitation":"poc","Technical Impact":"partial"},"version":"2.0.3"}},"references":[],"title":"Hikvision Integrated Security Management Platform Remote Command Execution via applyCT Fastjson","updated":"2025-07-02T20:25:11.993000+00:00","vendors":[],"vulnrichment_repo_path":"2025/34xxx/CVE-2025-34067.json","weaknesses":[]}}