CVE-2025-39247 is a high-severity access control vulnerability affecting some versions of Hikvision HikCentral Professional. According to the provided content, the flaw allows a remote, unauthenticated attacker to obtain administrative permissions on an affected HikCentral Professional system. Publicly available information indicates the issue stems from a failure in the product's access control mechanisms, but specific technical details such as the vulnerable endpoint, code path, function, or request sequence have not been publicly disclosed in the provided sources. HikCentral Professional is a centralized management platform for video surveillance, access control, and alarm systems, so compromise of the administrative role can expose core security-management functions.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a README with reverse-engineering notes and one Python PoC at poc/cve_2025_39247_poc.py. The PoC targets Hikvision HikCentral Professional CVE-2025-39247, an unauthenticated web vulnerability affecting V2.3.1-V2.6.2 and V3.0.0. The exploit chain is: initialize a session via /Security/Crypto, request the pre-auth QR endpoint /ISAPI/Bumblebee/Platform/V1/License/ActiveCode/QRCode?MT=GET&SID=<sid>, decode the returned PNG QR code, extract the SN/base64 ciphertext from the embedded Hikvision URL, and decrypt it using hardcoded AES-128-CBC key/IV constants (QR_KEY=WwXxYyZz1234!@#$, QR_IV=AaBbCcDd1234!@#$). The decrypted plaintext reveals license ActiveCode values and a device code. Those ActiveCode values can then be used in the product's forgot-password workflow against /Permission/ChangeDefaultUserPassword to reset the default admin password, resulting in admin takeover. The script explicitly does not automate the final reset; it prints the recovered codes and manual UI steps. The README provides substantial binary-diffing context, installer acquisition URLs, extracted archive layout, and patch analysis showing that V2.6.3 restricts the password-reset endpoint to 127.0.0.1 and removes the sensitive QR plaintext. Overall, this is a real operational PoC for a pre-auth information leak that enables subsequent unauthorized admin password reset on vulnerable, licensed HCMP deployments.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Unknown (listed as a trending CVE for Hikvision HikCentral without details in the content).
A high-severity access control vulnerability in Hikvision HikCentral Professional that allows unauthenticated network attackers to escalate privileges and gain full administrative control of the management platform.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.