Hikvision Vulnerabilities and Affected Products
Vulnerabilities associated with DS-3WAP522-SI.
Products
Clear product- DS-2CD Series5 vulnerabilities
- HikCentral Professional5 vulnerabilities
- DS-2DE Series4 vulnerabilities
- DS-3WAP521-SI3 vulnerabilities
- DS-3WAP522-SI3 vulnerabilities
- DS-3WAP621E-SI3 vulnerabilities
- DS-3WAP622E-SI3 vulnerabilities
- DS-3WAP622G-SI3 vulnerabilities
- DS-3WAP623E-SI3 vulnerabilities
- DS-A71024/48/72R,DS-A80624S,DS-A81016S,DS-A72024/72R,DS-A80316S,DS-A82024D3 vulnerabilities
- DS-A71024/48R-CVS,DS-A72024/48R-CVS3 vulnerabilities
- DS-K1T341C3 vulnerabilities
- HikCentral Master Lite3 vulnerabilities
- Intercom Broadcasting System3 vulnerabilities
- CSMP (Comprehensive Security Management Platform) iSecure Center2 vulnerabilities
- CSMP iSecure Center2 vulnerabilities
- DS-7104HGHI-F12 vulnerabilities
- DS-7204HGHI-F12 vulnerabilities
- DS-7604NI-K1 / 4P(B)2 vulnerabilities
- DS-76xxNI-Mx2 vulnerabilities
- DS-77xxNI-Mx2 vulnerabilities
- DS-K1T320XXX2 vulnerabilities
- DS-K1T341AXX2 vulnerabilities
- DS-K1T343XXX2 vulnerabilities
- DS-K1T671XXX2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-16843HIGH | Generated title:Hikvision Networking Products OS Command InjectionSome Hikvision Networking Products are vulnerable to authenticated command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution. CWE-78Jul 31, 2026 | CVSS7.2v3.1 | EPSS0.891% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-0709HIGH | Generated title:Hikvision Wireless Access Points Authenticated OS Command InjectionSome Hikvision Wireless Access Points are vulnerable to authenticated command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution. CWE-78Jan 30, 2026 | CVSS7.2v3.1 | EPSS0.821% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-39240HIGH | Some Hikvision Wireless Access Point are vulnerable to authenticated remote command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution. CWE-78Jun 13, 2025 | CVSS7.2v3.1 | EPSS1.14% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |