
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-39247 is an improper access control vulnerability (CWE-284) in Hikvision HikCentral Professional that allows an unauthenticated remote attacker to obtain administrative permissions without any user interaction. The vulnerability affects HikCentral Professional versions between V2.3.1 and V2.6.2, as well as version V3.0.0. It was published on August 29, 2025, with Hikvision as the assigning authority. The CVSS v3.1 base score is 8.6 (High), reflecting network-based exploitation with no privileges or user interaction required and a changed scope with high confidentiality impact (Hikvision Advisory, ENISA EUVD).
The root cause is classified as CWE-284 (Improper Access Control) / CWE-862 (Missing Authorization), meaning the application fails to properly enforce authorization checks on certain endpoints or operations, allowing unauthenticated requests to be treated as having administrative privileges. The attack vector is network-based with low complexity — an attacker can send a crafted HTTP request to the HikCentral Professional server without any credentials to gain admin-level access. A technical write-up titled "How a Single Request Grants Full Admin Control" has been published, suggesting the exploit may involve a specially crafted API or web request that bypasses authentication logic entirely (Undercode Testing, ZeroPath Blog).
Successful exploitation grants an unauthenticated attacker full administrative control over the HikCentral Professional platform, which is a centralized video surveillance management system. This could lead to unauthorized access to live and recorded video feeds, manipulation of surveillance configurations, creation of rogue admin accounts, and potential use of the compromised system as a pivot point for lateral movement within the network. The changed scope in the CVSS score reflects that the impact extends beyond the vulnerable component itself, potentially affecting connected cameras, access control systems, and other integrated security infrastructure (Hikvision Advisory, Security Affairs).
As of the time of reporting, there is no confirmed public proof-of-concept exploit or evidence of active in-the-wild exploitation (Feedly Executive Summary). However, a GitHub repository (Sita-Technologies/CVE-2025-39247) and a detailed technical write-up describing how a single request can grant full admin control have been published, significantly lowering the barrier to exploitation (GitHub PoC, Undercode Testing). The EPSS score is approximately 0.043%, indicating currently low predicted exploitation probability, and the vulnerability has not been added to the CISA KEV catalog as of this writing. CVE-2025-39247 was included in CISA's weekly vulnerability bulletin for the week of August 25, 2025 (CISA Bulletin).
Hikvision has published a security advisory for CVE-2025-39247 and related vulnerabilities in HikCentral products; users should consult the official advisory for patched version information and apply updates immediately (Hikvision Advisory). As interim workarounds: isolate HikCentral Professional systems from untrusted or public networks using firewalls and network segmentation; restrict access to the HikCentral web interface to trusted IP ranges only; monitor for unauthorized administrative access; and consider temporarily disabling the service if exposure cannot be controlled. Organizations should contact Hikvision support for specific patch availability for their version (Feedly Executive Summary).
The vulnerability received notable coverage from security media outlets including GBHackers, Security Affairs, SecurityOnline, and The Hacker News (in a weekly recap), highlighting the severity of unauthenticated admin access in a widely deployed physical security platform (GBHackers, Security Affairs, The Hacker News). Security researchers on Mastodon/Infosec.exchange and Bluesky flagged the vulnerability shortly after disclosure, noting the critical nature of admin bypass in surveillance infrastructure (Infosec.exchange). Red Hot Cyber published an article specifically highlighting the risk to video surveillance systems under the headline "Video Surveillance Under Attack" (Red Hot Cyber).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."