VYPR

iSecure Center

by Hikvision

CVEs (3)

  • CVE-2023-28815CriOct 17, 2025
    risk 0.64cvss 9.8epss 0.00

    Some versions of Hikvision's iSecure Center Product contain insufficient parameter validation, resulting in a command injection vulnerability. Attackers may exploit this to gain platform privileges and execute arbitrary commands on the system.iSecure Center is software released…

  • CVE-2023-28814CriOct 17, 2025
    risk 0.64cvss 9.8epss 0.00

    Some versions of Hikvision's iSecure Center Product have an improper file upload control vulnerability. Due to the improper verification of file to be uploaded, attackers may upload malicious files to the server. iSecure Center is software released for China's domestic market…

  • CVE-2024-58274HigOct 22, 2025
    risk 0.54cvss 8.3epss 0.00

    Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2024-08-01 allows execution of a command within $( ) in /center/api/installation/detection JSON data, as exploited in the wild in 2024 and 2025.