Record summary

CVE-2023-6895 has a selected CVSS score of 6.3 (medium); EIP currently links 2 repository PoCs and 1 Nuclei template.

Description

A vulnerability was found in Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK). It has been declared as critical. This vulnerability affects unknown code of the file /php/ping.php. The manipulation of the argument jsondata[ip] with the input netstat -ano leads to os command injection. The exploit has been disclosed to the public and may be used. Upgrading to version 4.1.0 is able to address this issue. It is recommended to upgrade the affected component. VDB-248254 is the identifier assigned to this vulnerability.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Feb 23, 2026 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
2
Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 21, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List3.0.3_20201113_RELEASE(HIK)affected
VulnCheckVersion data not supplied

Proofs of concept

2

Repository PoCs

GitHubFuBoLuSec/CVE-2023-6895Repository PoCby FuBoLuSecStars: 1Not analyzed2 files

2.4 KiB

GitHub

PoC details
GitHubnles-crt/CVE-2023-6895Repository PoCby nles-crtStars: 0Not analyzed2 files

3.3 KiB · linked to 2 vulnerabilities

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryCRITICALHikvision IP ping.php - Command ExecutionCVSS 9.8

A vulnerability was found in Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK). It has been declared as critical. This vulnerability affects unknown code of the file /php/ping.php. The manipulation of the argument jsondata[ip] with the input netstat -ano leads to os command injection. The exploit has been disclosed to the public and may be used. Upgrading to version 4.1.0 is able to address this issue. It is recommended to upgrade the affected component. VDB-248254 is the identifier assigned to this vulnerability.

Impact

Unauthenticated attackers can execute arbitrary operating system commands via the jsondata[ip] parameter, potentially gaining complete control over the Hikvision Intercom Broadcasting System.

Remediation

Upgrade to Hikvision Intercom Broadcasting System version 4.1.0 or later.

WeaknessesCWE-78
AuthorsDhiyaneshDk, archer
Template tagscvecve2023hikvisionrcevulnvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:o:hikvision:intercom_broadcast_system:*:*:*:*:*:*:*:*
Shodan: http.favicon.hash:"-1830859634"
FOFA: icon_hash="-1830859634"

Source: ProjectDiscovery

References

4