CVE-2025-34058: Hikvision Streaming Media Management Server Default Credentials and Authenticated Arbitrary File Read
Hikvision Streaming Media Management Server v2.3.5 uses default credentials that allow remote attackers to authenticate and access restricted functionality. After authenticating with these credentials, an attacker can exploit an arbitrary file read vulnerability in the /systemLog/downFile.php endpoint via directory traversal in the fileName parameter. This exploit chain can enable unauthorized access to sensitive system files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-34058?
CVE-2025-34058 is of high severity due to the use of default credentials which allows unauthorized access.
How do I fix CVE-2025-34058?
To fix CVE-2025-34058, change the default credentials to strong, unique passwords immediately.
What are the potential consequences of CVE-2025-34058?
The potential consequences of CVE-2025-34058 include unauthorized access to sensitive functionalities and possible exploitation of related vulnerabilities.
Who is affected by CVE-2025-34058?
CVE-2025-34058 affects users of Hikvision Streaming Media Management Server v2.3.5.
Can CVE-2025-34058 lead to further attacks?
Yes, CVE-2025-34058 can lead to further attacks, including arbitrary file read vulnerabilities if exploited successfully.