Hikvision HikCentral applyCT Vulnerability (CVE-2025-34067): What It Is and How to Respond
The HIKVISION ApplyCT Vulnerability (CVE-2025-34067) is a critical remote code execution flaw in the HikCentral Integrated Security Management Platform. It allows unauthenticated attackers to execute arbitrary code remotely by exploiting a weakness in the Fastjson library used by the applyCT component. With a CVSS score of 10.0, this flaw exposes millions of Hikvision surveillance devices to serious compromise, including the risk of full system control and data leaks. The vulnerability highlights the urgent need for firmware updates and secure coding practices in embedded systems.
Quick answer: CVE-2025-34067 is a critical flaw in Hikvision HikCentral, the platform that manages cameras and recorders. The applyCT endpoint processes JSON with a vulnerable Fastjson version, which can allow unauthenticated remote code execution. Defenders should check the vendor advisory for fixed versions, patch, restrict network access to the platform and monitor for odd outbound connections.
Key takeaways
- CVE-2025-34067 affects the HikCentral management platform, not the cameras themselves.
- The cause is unsafe deserialization in an outdated Fastjson library reached through the applyCT endpoint.
- It is rated critical and can be exploited over the network without logging in. Check NVD for the current score and affected versions.
- Patch using the vendor advisory, and keep management platforms off the open internet.
- Watch for unexpected outbound LDAP or HTTP calls and new processes from the HikCentral host.
What is CVE-2025-34067?
It is a vulnerability in the Hikvision HikCentral Integrated Security Management Platform, software used to manage cameras, recorders and access systems from one place. The record describes an issue in the /bic/ssoService/v1/applyCT endpoint, where untrusted JSON is handled by an old version of the Fastjson library. It was published in July 2025 and is rated critical. Read the live entry on the National Vulnerability Database for the current score, affected versions and references.
The earlier version of this page described the platform as controlling millions of devices and gave a fixed version number and a timeline of dates. We could not verify those against the vendor advisory, so they are not repeated here. Use the vendor advisory as the authority on versions.
How does the flaw work?
Fastjson converts JSON text into Java objects. When a feature called auto-type is enabled in older versions, a request can name the Java class to create. If an attacker can steer that choice, the server may be made to load code from a location the attacker controls. This class of bug is called insecure deserialization, and it sits under the OWASP Top 10 as software and data integrity failures.
The key points for a defender:
- The request goes to a single sign-on related endpoint, so it may be reachable before login.
- Success gives code execution as the account that runs the HikCentral service, which on many servers has wide access.
- A compromised management server is a route to every device and video feed it controls.
Are you affected?
- Find every HikCentral server in your asset list, including ones set up by contractors.
- Read the version from the admin interface and compare it with the vendor advisory.
- Check exposure. Is the web interface reachable from the internet or from user networks that do not need it?
- Review logs from before patching for requests to the applyCT path.
How do you fix and reduce the risk?
- Patch to the version named in the vendor advisory. If you cannot upgrade immediately, follow the vendor's mitigation guidance and block access to the vulnerable path at a reverse proxy or firewall.
- Remove internet exposure. Put management platforms behind a VPN or an allow-list.
- Segment the network. Keep cameras and the management server in their own VLAN, with only needed flows allowed.
- Limit egress. A server that has no reason to make LDAP or arbitrary outbound HTTP calls should be blocked from doing so.
- Run the service with least privilege rather than as an administrator.
How can you detect exploitation attempts?
Look for these signs on or near the HikCentral host:
- Outbound LDAP or RMI connections to unfamiliar addresses.
- The Java process launching a shell,
cmd.exeorpowershell.exe. - New scheduled tasks, services or admin accounts after unusual requests.
- Web requests to the applyCT path with a JSON body that contains an
@typekey.
Write detections that match your own logging, then test them in a lab copy. Do not test against systems you do not own. For other recent critical flaws, read our notes on the SharePoint CVE-2025-53770 exploitation and the Nessus file overwrite issue, and on unpatched Active Directory flaws.
Lessons for security teams
- Track third-party libraries inside products. A software bill of materials makes this easier.
- Treat physical security systems as part of the IT estate, with patching and ownership.
- Do not publish management consoles to the internet.
Next steps
Next steps: to learn to triage alerts like these, see our Certified SOC Analyst course, and read about the SharePoint CVE-2025-53770 exploitation.
Related reading
Frequently Asked Questions
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0