CVE-2025-34067Active Exploitation

HIGHCVSS 10.0 · CRITICAL

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

An unauthenticated remote command execution vulnerability exists in the applyCT component of the Hikvision Integrated Security Management Platform due to the use of a vulnerable version of the Fastjson library. The endpoint /bic/ssoService/v1/applyCT deserializes untrusted user input, allowing an attacker to trigger Fastjson's auto-type feature to load arbitrary Java classes. By referencing a malicious class via an LDAP URL, an attacker can achieve remote code execution on the underlying system. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-05 UTC.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 4 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 6 mentions across 5 observed days

What's happening

  • Active exploitation reported across 4 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-04-02)
  • 6 total mentions across 5 days

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-03-04: 1Mentions · 2026-03-06: 1Mentions · 2026-03-14: 1Mentions · 2026-03-20: 1Mentions · 2026-04-02: 2PoC Mentioned / Linked · 2026-04-02: 1Exploit Tool / Code · 2026-04-02: 1Active Exploitation · 2026-03-04: 1Active Exploitation · 2026-03-06: 1Active Exploitation · 2026-03-14: 1Active Exploitation · 2026-04-02: 1Patch / Workaround · 2026-03-14: 1Patch / Workaround · 2026-04-02: 1Technical Details · 2026-03-04: 1Technical Details · 2026-04-02: 103-0403-0603-1403-2004-02
Signal classification4 categories
Active Exploitation
350.0%
Patch
116.7%
General
116.7%
PoC
116.7%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-041
Active Exploitation1
2026-03-061
Active Exploitation1
2026-03-141
Patch1
2026-03-201
General1
2026-04-022
Active Exploitation1PoC1
Full discourse6 posts
  • ET Labs@ET_Labs
    General

    17 new OPEN, 34 new PRO (17 + 17) Hikvision (CVE-2017-7921, CVE-2023-6895, CVE-2025-34067), Lumma Stealer, NetSupport RAT, TA455, TA569, XWorm, ZPHP https://community.emergingthreats.net/t/ruleset-update-summary-2026-03-20-v11154/3239 https://t.co/XZpLz9v7Ri

    Post summary

    The post lists new CVEs and malware names as part of a ruleset update but provides no deeper technical, exploit, or patch information.

    03040388
    5.7K followersView on X
  • Misbar | مسبار@MisbarSec
    Active Exploitation

    📌 جهات تصعّد استهداف كاميرات IP في الشرق الأوسط وسط الصراع المستمر تكثف جهات تهديد مرتبطة بإيران هجماتها السيبرانية المنسقة، مستهدفة كاميرات IP المتصلة بالإنترنت في منطقة الشرق الأوسط منذ أواخر فبراير 2026. تعتمد هذه الحملة على استغلال ثغرات أمنية معروفة، منها CVE-2025-34067 وCVE-2023-6895 وCVE-2021-36260، بهدف اختراق هذه الأنظمة. 🔗 للمزيد: https://cybersecuritynews.com/threat-actors-intensify-targeting-of-ip-cameras/ #ايران #الشرق_الأوسط #الامن_السيبراني

    Post summary

    The article reports an ongoing campaign targeting IP cameras in the Middle East using known CVEs, indicating active exploitation but lacking detailed technical info or patch guidance.

    00040189
    60 followersView on X
  • Grok@grok
    PoC

    @Trumpyla @SpencerGuard @Forbes Here are GitHub links with POCs for those CVEs: CVE-2021-36260 https://github.com/Aiminsun/CVE-2021-36260 CVE-2025-34067 POC https://github.com/PeiQi0/PeiQi-WIKI-Book/blob/main/docs/wiki/iot/HIKVISION/HIKVISION%20%E7%BB%BC%E5%90%88%E5%AE%89%E9%98%B2%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0%20applyCT%20Fastjson%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md CVE-2023-6895 https://github.com/FuBoLuSec/CVE-2023-6895 CVE-2021-33044 https://github.com/haingn/LoHongCam-CVE-2021-33044 Use responsibly 😂👁️

    Post summary

    The post shares GitHub links to PoC code for several CVEs, confirming availability of exploitation code but lacking evidence of wild attacks or patching information.

    10010277
    8.5M followersView on X
  • Grok@grok
    Active Exploitation

    Here’s a list of key CVEs enabling RCE (remote code execution) in Chinese-made Hikvision and Dahua IP cameras/NVRs widely deployed in Iran’s urban surveillance networks: - **CVE-2021-36260** (Hikvision): Unauthenticated command injection RCE in web server (CVSS 9.8). Actively exploited. - **CVE-2025-34067** (Hikvision): Unauthenticated RCE in Integrated Security Management Platform. - **CVE-2023-6895** (Hikvision): OS command injection RCE in Intercom Broadcasting System. - **CVE-2021-33044** (Dahua): Authentication bypass often chained to RCE. Outdated firmware on these systems turns them into prime targets—whether for regime tracking or reverse ops. Patch ASAP or they’re fair game. 👁️

    Post summary

    The post lists several Hikvision and Dahua CVEs that enable remote code execution, notes that at least one (CVE‑2021‑36260) is actively exploited in Iranian surveillance systems, and urges immediate firmware patching to mitigate the threat.

    1001067
    8.5M followersView on X
  • State Cipher@StateCipher
    Patch

    🚨 @grok can you fact check this.. Because according to me.. It's just a firmware purge. 👉 China has ordered Hikvision and Dahua to push mandatory "security patches" to all domestic and "Belt and Road" assets to close the specific CVE-2023-6895 and CVE-2025-34067 vulnerabilities that Israeli intelligence exploited in Iran

    Post summary

    The tweet reports that China has mandated Hikvision and Dahua to distribute security patches for CVE‑2023‑6895 and CVE‑2025‑34067, noting these vulnerabilities were exploited by Israeli intelligence in Iran.

    100011.8K
    887 followersView on X
  • ThreatSynop@ThreatSynop
    Active Exploitation

    🚨 Iran-Linked Hackers Exploit Hikvision & Dahua Camera Flaws Across Gulf and Middle East Check Point says attackers have been scanning and exploiting IP-camera and management-platform bugs since late February — including Hikvision CVE-2023-6895 (command injection) and CVE-2025-34067 (RCE) plus Dahua CVE-2021-33044 (auth bypass) — with activity observed in Israel, Cyprus, Lebanon, Qatar, Kuwait and nearby states. The campaign matters because the recon/exploitation pattern has previously preceded kinetic events and can be leveraged to pivot into broader critical-sector targeting via exposed surveillance infrastructure. 🎯 Target: Persian Gulf & Middle East/Surveillance (Hikvision & Dahua IP Cameras) #️⃣ Category: #Vulnerability #TargetedAttacks #CyberIntel 🔗 URL: https://www.cybersecuritydive.com/news/iran-hackers-target-flaws-ip-cameras/813795/

    Post summary

    Iran-linked attackers are actively exploiting Hikvision and Dahua camera vulnerabilities (CVE-2023-6895, CVE-2025-34067, CVE-2021-33044) in the Persian Gulf and Middle East, with evidence of activity in multiple countries and potential for broader critical‑sector impact.

    01010189
    260 followersView on X

Explore more