CVE Database
/

CVE-2025-34058

Back to search

CVE-2025-34058

Published: Jul 1, 2025

Modified: Jul 1, 2025

PUBLISHED

Description

Hikvision Streaming Media Management Server v2.3.5 uses default credentials that allow remote attackers to authenticate and access restricted functionality. After authenticating with these credentials, an attacker can exploit an arbitrary file read vulnerability in the /systemLog/downFile.php endpoint via directory traversal in the fileName parameter. This exploit chain can enable unauthorized access to sensitive system files.

VendorProductVersions

Hangzhou Hikvision System Technology

Streaming Media Management Server

affected
2.3.5

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now