CVE-2024-58274
48Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck.
ssvc Actcvss 8.3epss 18%
from disclosure to weapon
Published on NVDOct 22
VulnCheckOct 22
exploitation probability
18%top 3% of all CVEs
observed exploitation
yesVulnCheck
Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2024-08-01 allows execution of a command within $( ) in /center/api/installation/detection JSON data, as exploited in the wild in 2024 and 2025.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
Affected products
Hikvision · CSMP iSecure Center