Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2025-39247
Hikvision HikCentral Professional vulnerability analysis and mitigation

Overview

CVE-2025-39247 is an improper access control vulnerability (CWE-284) in Hikvision HikCentral Professional that allows an unauthenticated remote attacker to obtain administrative permissions without any user interaction. The vulnerability affects HikCentral Professional versions between V2.3.1 and V2.6.2, as well as version V3.0.0. It was published on August 29, 2025, with Hikvision as the assigning authority. The CVSS v3.1 base score is 8.6 (High), reflecting network-based exploitation with no privileges or user interaction required and a changed scope with high confidentiality impact (Hikvision Advisory, ENISA EUVD).

Technical details

The root cause is classified as CWE-284 (Improper Access Control) / CWE-862 (Missing Authorization), meaning the application fails to properly enforce authorization checks on certain endpoints or operations, allowing unauthenticated requests to be treated as having administrative privileges. The attack vector is network-based with low complexity — an attacker can send a crafted HTTP request to the HikCentral Professional server without any credentials to gain admin-level access. A technical write-up titled "How a Single Request Grants Full Admin Control" has been published, suggesting the exploit may involve a specially crafted API or web request that bypasses authentication logic entirely (Undercode Testing, ZeroPath Blog).

Impact

Successful exploitation grants an unauthenticated attacker full administrative control over the HikCentral Professional platform, which is a centralized video surveillance management system. This could lead to unauthorized access to live and recorded video feeds, manipulation of surveillance configurations, creation of rogue admin accounts, and potential use of the compromised system as a pivot point for lateral movement within the network. The changed scope in the CVSS score reflects that the impact extends beyond the vulnerable component itself, potentially affecting connected cameras, access control systems, and other integrated security infrastructure (Hikvision Advisory, Security Affairs).

Exploitability

As of the time of reporting, there is no confirmed public proof-of-concept exploit or evidence of active in-the-wild exploitation (Feedly Executive Summary). However, a GitHub repository (Sita-Technologies/CVE-2025-39247) and a detailed technical write-up describing how a single request can grant full admin control have been published, significantly lowering the barrier to exploitation (GitHub PoC, Undercode Testing). The EPSS score is approximately 0.043%, indicating currently low predicted exploitation probability, and the vulnerability has not been added to the CISA KEV catalog as of this writing. CVE-2025-39247 was included in CISA's weekly vulnerability bulletin for the week of August 25, 2025 (CISA Bulletin).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or network-accessible HikCentral Professional instances running versions V2.3.1–V2.6.2 or V3.0.0 using tools like Shodan, Censys, or Fofa, searching for HikCentral web interfaces (typically on port 443 or 80).
  2. Identify vulnerable endpoint: Based on the "single request" nature of the exploit, probe the HikCentral Professional web API for endpoints that handle administrative functions without enforcing authentication checks (e.g., user management, configuration, or session APIs).
  3. Craft unauthenticated request: Send a specially crafted HTTP request to the identified endpoint — potentially manipulating headers, parameters, or request structure to bypass the authorization check — without supplying valid credentials.
  4. Obtain admin session: The server processes the request as if it originated from an authenticated administrator, returning an admin session token, cookie, or directly executing the privileged action.
  5. Achieve full admin control: Use the obtained administrative access to enumerate connected cameras, modify surveillance configurations, create persistent backdoor accounts, exfiltrate recorded footage, or pivot to other systems on the network (Undercode Testing, ZeroPath Blog).

Indicators of compromise

  • Network: Unexpected HTTP/HTTPS requests to HikCentral Professional administrative API endpoints from unauthenticated or external IP addresses; unusual outbound connections from the HikCentral server to unknown external hosts.
  • Logs: HikCentral access logs showing administrative actions (user creation, configuration changes, session establishment) with no corresponding prior authentication event; repeated requests to sensitive API endpoints from a single IP without login attempts.
  • Application: Unexpected new administrator accounts created in HikCentral Professional; changes to system configuration, camera settings, or recording schedules without corresponding authorized user activity.
  • Process/System: Unusual processes spawned by the HikCentral service; unexpected outbound network connections from the HikCentral server host to external IPs (Security Affairs, Undercode Testing).

Mitigation and workarounds

Hikvision has published a security advisory for CVE-2025-39247 and related vulnerabilities in HikCentral products; users should consult the official advisory for patched version information and apply updates immediately (Hikvision Advisory). As interim workarounds: isolate HikCentral Professional systems from untrusted or public networks using firewalls and network segmentation; restrict access to the HikCentral web interface to trusted IP ranges only; monitor for unauthorized administrative access; and consider temporarily disabling the service if exposure cannot be controlled. Organizations should contact Hikvision support for specific patch availability for their version (Feedly Executive Summary).

Community reactions

The vulnerability received notable coverage from security media outlets including GBHackers, Security Affairs, SecurityOnline, and The Hacker News (in a weekly recap), highlighting the severity of unauthenticated admin access in a widely deployed physical security platform (GBHackers, Security Affairs, The Hacker News). Security researchers on Mastodon/Infosec.exchange and Bluesky flagged the vulnerability shortly after disclosure, noting the critical nature of admin bypass in surveillance infrastructure (Infosec.exchange). Red Hot Cyber published an article specifically highlighting the risk to video surveillance systems under the headline "Video Surveillance Under Attack" (Red Hot Cyber).

Additional resources


SourceThis report was generated using AI

Related Hikvision HikCentral Professional vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-39247HIGH8.6
  • Hikvision HikCentral Professional logoHikvision HikCentral Professional
  • cpe:2.3:a:hikvision:hikcentral_professional
NoNoAug 29, 2025
CVE-2024-25063HIGH7.5
  • Hikvision HikCentral Professional logoHikvision HikCentral Professional
  • cpe:2.3:a:hikvision:hikcentral_professional
NoYesMar 02, 2024
CVE-2024-47487HIGH7.2
  • Hikvision HikCentral Professional logoHikvision HikCentral Professional
  • cpe:2.3:a:hikvision:hikcentral_professional
NoYesOct 18, 2024
CVE-2024-25064MEDIUM4.3
  • Hikvision HikCentral Professional logoHikvision HikCentral Professional
  • cpe:2.3:a:hikvision:hikcentral_professional
NoYesMar 02, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management