Hikvision Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with Hikvision products.
Products
- DS-2CD Series5 vulnerabilities
- HikCentral Professional5 vulnerabilities
- DS-2DE Series4 vulnerabilities
- DS-3WAP521-SI3 vulnerabilities
- DS-3WAP522-SI3 vulnerabilities
- DS-3WAP621E-SI3 vulnerabilities
- DS-3WAP622E-SI3 vulnerabilities
- DS-3WAP622G-SI3 vulnerabilities
- DS-3WAP623E-SI3 vulnerabilities
- DS-A71024/48/72R,DS-A80624S,DS-A81016S,DS-A72024/72R,DS-A80316S,DS-A82024D3 vulnerabilities
- DS-A71024/48R-CVS,DS-A72024/48R-CVS3 vulnerabilities
- DS-K1T341C3 vulnerabilities
- HikCentral Master Lite3 vulnerabilities
- Intercom Broadcasting System3 vulnerabilities
- CSMP (Comprehensive Security Management Platform) iSecure Center2 vulnerabilities
- CSMP iSecure Center2 vulnerabilities
- DS-7104HGHI-F12 vulnerabilities
- DS-7204HGHI-F12 vulnerabilities
- DS-7604NI-K1 / 4P(B)2 vulnerabilities
- DS-76xxNI-Mx2 vulnerabilities
- DS-77xxNI-Mx2 vulnerabilities
- DS-K1T320XXX2 vulnerabilities
- DS-K1T341AXX2 vulnerabilities
- DS-K1T343XXX2 vulnerabilities
- DS-K1T671XXX2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-16843HIGH | Generated title:Hikvision Networking Products OS Command InjectionSome Hikvision Networking Products are vulnerable to authenticated command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution. CWE-78Jul 31, 2026 | CVSS7.2v3.1 | EPSS0.891% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-61392MEDIUM | Generated title:Hikvision DS-2CD and DS-2DE Series Cameras Information Disclosure VulnerabilityThere is a information disclosure vulnerability in some Hikvision cameras, allowing unauthenticated attackers to obtain partial information from the device’s memory. CWE-200Jul 22, 2026 | CVSS5.3v3.1 | EPSS0.206% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-61391HIGH | Generated title:Hikvision DS-2CD and DS-2DE Series Cameras Stack-based Buffer OverflowThere is a stack-based buffer overflow vulnerability in some Hikvision cameras, which may allow authenticated attackers to cause device malfunction by sending specially crafted packets. CWE-121Jul 22, 2026 | CVSS7.2v3.1 | EPSS0.304% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-61390HIGH | Generated title:Hikvision DS-2CD and DS-2DE Series Cameras Heap Buffer OverflowThere is a heap buffer overflow vulnerability in some Hikvision cameras, which may allow unauthenticated attackers to cause device malfunction by sending specially crafted packets. CWE-122Jul 22, 2026 | CVSS7.7v3.1 | EPSS0.228% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-57600HIGH | Generated title:Hikvision DS-2CD, DS-2DE, DS-2DP, and DS-2TD Series Cameras Improper Input Validation Leading to Sensitive Information DisclosureInsufficient validation of input parameters in the firmware of some Hikvision cameras allows unauthenticated attackers to retrieve partial sensitive data. CWE-20Jul 22, 2026 | CVSS7.5v3.1 | EPSS0.248% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-57599MEDIUM | Generated title:Hikvision DS-2CD Series Cameras Privilege Escalation via Incorrect Permission AllocationThere is a privilege escalation vulnerability in some Hikvision cameras. Due to incorrect permission allocation in the device program, attackers can escalate privileges and gain full control of the device after authenticating via SSH. CWE-269Jul 22, 2026 | CVSS6.6v3.1 | EPSS0.211% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Generated title:Hikvision Hik-Connect APP Incorrect Directory Permission Assignment Leading to Information DisclosureThe application does not impose strict enough restrictions on directory access permissions, posing a risk that other malicious applications could obtain sensitive information. CWE-732May 12, 2026 | CVSS2.9v3.1 | EPSS0.092% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2026-3828HIGH | Generated title:Hikvision DS-3E1310P-SI and DS-3E1326P-SI Authenticated OS Command Injection VulnerabilitySome Hikvision switch products (discontinued since December 2023) are vulnerable to authenticated remote command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution. CWE-78May 9, 2026 | CVSS7.2v3.1 | EPSS0.842% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-1749MEDIUM | Generated title:Hikvision HikCentral Professional Access Control VulnerabilityThere is an Access Control Vulnerability in some HikCentral Professional versions. This could allow an unauthenticated user to obtain the admin permission. CWE-284May 9, 2026 | CVSS6.8v3.1 | EPSS0.282% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-0709HIGH | Generated title:Hikvision Wireless Access Points Authenticated OS Command InjectionSome Hikvision Wireless Access Points are vulnerable to authenticated command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution. CWE-78Jan 30, 2026 | CVSS7.2v3.1 | EPSS0.821% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-66177HIGH | There is a Buffer overflow Vulnerability in the device Search and Discovery feature of Hikvision NVR/DVR/CVR/IPC models. If exploited, an attacker on the same local area network (LAN) could cause the device to malfunction by sending specially crafted packets to an unpatched device. CWE-121Jan 13, 2026 | CVSS8.8v3.1 | EPSS0.339% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-66176HIGH | There is a Buffer overflow Vulnerability in the device Search and Discovery feature of Hikvision Access Control Products. If exploited, an attacker on the same local area network (LAN) could cause the device to malfunction by sending specially crafted packets to an unpatched device. CWE-121Jan 13, 2026 | CVSS8.8v3.1 | EPSS0.509% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-66174MEDIUM | There is an improper authentication vulnerability in some Hikvision DVR products. Due to the improper implementation of authentication for the serial port, an attacker with physical access could exploit this vulnerability by connecting to the affected products and run a series of commands. CWE-287Dec 19, 2025 | CVSS6.5v3.1 | EPSS0.324% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-66173MEDIUM | There is a privilege escalation vulnerability in some Hikvision DVR products. Due to the improper implementation of authentication for the serial port, an attacker with physical access could exploit this vulnerability by connecting to the affected products and gaining access to an unrestricted shell environment. CWE-269Dec 19, 2025 | CVSS6.2v3.1 | EPSS0.196% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-53691HIGH | Path Traversal: '../filedir'Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2023-06-25 allows file upload via /center/api/files directory traversal, as exploited in the wild in 2024 and 2025. CWE-24Oct 22, 2025 | CVSS8.3v3.1 | EPSS1.2% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-58274HIGH | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2024-08-01 allows execution of a command within $( ) in /center/api/installation/detection JSON data, as exploited in the wild in 2024 and 2025. CWE-78Oct 22, 2025 | CVSS8.3v3.1 | EPSS17.9% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-28815CRITICAL | Some versions of Hikvision's iSecure Center Product contain insufficient parameter validation, resulting in a command injection vulnerability. Attackers may exploit this to gain platform privileges and execute arbitrary commands on the system.iSecure Center is software released for China's domestic market only, with no overseas release. CWE-141Oct 17, 2025 | CVSS9.8v3.1 | EPSS1.46% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-28814CRITICAL | Some versions of Hikvision's iSecure Center Product have an improper file upload control vulnerability. Due to the improper verification of file to be uploaded, attackers may upload malicious files to the server. iSecure Center is software released for China's domestic market only, with no overseas release. CWE-434Oct 17, 2025 | CVSS9.8v3.1 | EPSS0.469% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-39247HIGH | There is an Access Control Vulnerability in some HikCentral Professional versions. This could allow an unauthenticated user to obtain the admin permission. CWE-284Aug 29, 2025 | CVSS8.6v3.1 | EPSS0.451% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-39246MEDIUM | There is an Unquoted Service Path Vulnerability in some HikCentral FocSign versions. This could allow an authenticated user to potentially enable escalation of privilege via local access. CWE-428Aug 29, 2025 | CVSS5.3v3.1 | EPSS0.327% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-39245MEDIUM | There is a CSV Injection Vulnerability in some HikCentral Master Lite versions. This could allow an attacker to inject executable commands via malicious CSV data. CWE-1236Aug 29, 2025 | CVSS4.7v3.1 | EPSS0.346% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-34067CRITICAL | Hikvision Integrated Security Management Platform Remote Command Execution via applyCT FastjsonAn unauthenticated remote command execution vulnerability exists in the applyCT component of the Hikvision Integrated Security Management Platform due to the use of a vulnerable version of the Fastjson library. The endpoint /bic/ssoService/v1/applyCT deserializes untrusted user input, allowing an attacker to trigger Fastjson's auto-type feature to load arbitrary Java classes. By referencing a malicious class via an LDAP URL, an attacker can achieve remote code execution on the underlying system.… CWE-502Jul 2, 2025 | CVSS10.0v4.0 | EPSS20.5% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-34058HIGH | Hikvision Streaming Media Management Server Default Credentials and Authenticated Arbitrary File ReadHikvision Streaming Media Management Server v2.3.5 uses default credentials that allow remote attackers to authenticate and access restricted functionality. After authenticating with these credentials, an attacker can exploit an arbitrary file read vulnerability in the /systemLog/downFile.php endpoint via directory traversal in the fileName parameter. This exploit chain can enable unauthorized access to sensitive system files. | CVSS8.7v4.0 | EPSS0.852% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-39240HIGH | Some Hikvision Wireless Access Point are vulnerable to authenticated remote command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution. CWE-78Jun 13, 2025 | CVSS7.2v3.1 | EPSS1.14% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
There is an XSS vulnerability in some HikCentral Master Lite versions. If exploited, an attacker could inject scripts into certain pages by building malicious data. CWE-79Oct 18, 2024 | CVSS2.1v4.0 | EPSS0.269% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |