CVE-2025-39240 Details
Description
Some Hikvision Wireless Access Point are vulnerable to authenticated remote command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution.
A vulnerability allowing authenticated remote command execution has been identified in certain Hikvision Wireless Access Point models. This issue arises from inadequate input validation, which enables attackers with valid credentials to send crafted packets containing malicious commands to the affected devices, resulting in arbitrary command execution.
Users can download the fixed version from the Hikvision official website. The specific patched version is V1.1.6300 build250331 (R2263).
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 13, 2025CISA-ADP
Assessed Jun 13, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Hikvision DS-3WAP622G-SI | <= V1.1.5402 build241014 (E2254P02) <= V1.1.5400 build240814 (E2254) |
CPE
Remediation
| |
| Hikvision DS-3WAP623E-SI | All versions |
CPE
Remediation
| |
| Hikvision DS-3WAP521-SI | All versions |
CPE
Remediation
| |
| Hikvision DS-3WAP522-SI | All versions |
CPE
Remediation
| |
| Hikvision DS-3WAP621E-SI | All versions |
CPE
Remediation
| |
| Hikvision DS-3WAP622E-SI | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2025 | CVE Modified | CISA-ADP |
| Jun 13, 2025 | New CVE Received | [email protected] |
Volerion