Some Hikvision Wireless Access Point are vulnerable to authenticated remote command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution.
Metrics
Affected Vendors & Products
References
History
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 17 Jun 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-78 |
Fri, 13 Jun 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 13 Jun 2025 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Some Hikvision Wireless Access Point are vulnerable to authenticated remote command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution. | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: hikvision
Published: 2025-06-13T07:10:39.734Z
Updated: 2025-06-17T17:24:32.221Z
Reserved: 2025-04-16T05:37:51.246Z
Link: CVE-2025-39240
Updated: 2025-06-13T15:15:55.290Z
Status : Awaiting Analysis
Published: 2025-06-13T08:15:19.377
Modified: 2025-06-17T18:15:25.770
Link: CVE-2025-39240
No data.