PT-2025-25398 · Hikvision · Hikvision Wireless Access Point

·

CVE-2025-39240

·

Published

2025-06-13

·

Updated

2025-06-18

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Hikvision Wireless Access Point (affected versions not specified)
Description The issue is related to insufficient input validation, allowing authenticated remote command execution. Attackers with valid credentials can exploit this by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-07275
CVE-2025-39240

Affected Products

Hikvision Wireless Access Point