CVE-2024-58274: OS Command Injection
Published Oct 22, 2025
·Updated
Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2024-08-01 allows execution of a command within $( ) in /center/api/installation/detection JSON data, as exploited in the wild in 2024 and 2025.
Affected Software
1 affected component
Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center<=2024-08-01
Event History
Oct 22, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-58274?
CVE-2024-58274 is classified as a critical vulnerability due to its potential for remote command execution.
2
How do I fix CVE-2024-58274?
To mitigate CVE-2024-58274, update the Hikvision CSMP iSecure Center software to a version later than 2024-08-01.
3
What systems are affected by CVE-2024-58274?
CVE-2024-58274 affects Hikvision CSMP iSecure Center versions up to and including 2024-08-01.
4
Is CVE-2024-58274 actively exploited?
Yes, CVE-2024-58274 has been reported to be exploited in the wild during 2024 and 2025.
5
What type of vulnerability is CVE-2024-58274?
CVE-2024-58274 is a remote code execution vulnerability that allows attackers to execute commands within the application.