Executive brief
A security vulnerability has been identified in Hikvision HikCentral Professional, a centralized video management platform used to manage security cameras and access control systems. An attacker could exploit this flaw to gain administrative permissions without needing a username or password. This could allow an unauthorized person to view sensitive video feeds or modify security system settings, potentially compromising the physical security of a facility.
Technical details
An improper access control vulnerability (CWE-284) exists in Hikvision HikCentral Professional versions V2.4.0 through V3.0.1. The flaw allows an unauthenticated attacker to bypass security restrictions and obtain administrative permissions. While the attack vector is network-based, the CVSS metric indicates high complexity (AC:H), suggesting specific conditions or timing may be required to successfully exploit the vulnerability. Successful exploitation results in a complete loss of confidentiality (C:H) as the attacker gains unauthorized access to the management interface. Users are advised to update to a patched version provided by the vendor.
Affected products
- Hikvision HikCentral Professional V2.4.0 - V3.0.1
Timeline
- 2026-05-09: disclosed
- 2026-05-09: advisory