Filtered by vendor Hikvision Subscriptions
Filtered by product Isecure Center Subscriptions
Total 4 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2023-53691 1 Hikvision 1 Isecure Center 2025-10-23 8.3 High
Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2023-06-25 allows file upload via /center/api/files directory traversal, as exploited in the wild in 2024 and 2025.
CVE-2024-58274 1 Hikvision 1 Isecure Center 2025-10-23 8.3 High
Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2024-08-01 allows execution of a command within $( ) in /center/api/installation/detection JSON data, as exploited in the wild in 2024 and 2025.
CVE-2023-28815 1 Hikvision 1 Isecure Center 2025-10-21 9.8 Critical
Some versions of Hikvision's iSecure Center Product contain insufficient parameter validation, resulting in a command injection vulnerability. Attackers may exploit this to gain platform privileges and execute arbitrary commands on the system.iSecure Center is software released for China's domestic market only, with no overseas release.
CVE-2023-28814 1 Hikvision 1 Isecure Center 2025-10-21 9.8 Critical
Some versions of Hikvision's iSecure Center Product have an improper file upload control vulnerability. Due to the improper verification of file to be uploaded, attackers may upload malicious files to the server. iSecure Center is software released for China's domestic market only, with no overseas release.