CVE-2026-57599

MEDIUM

Hikvision DS-2CD Series - Privilege Escalation

Title source: rule
STIX 2.1

Description

There is a privilege escalation vulnerability in some Hikvision cameras. Due to incorrect permission allocation in the device program, attackers can escalate privileges and gain full control of the device after authenticating via SSH.

Scores

CVSS v3 6.6
EPSS 0.0021
EPSS Percentile 11.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-269
Status published
Products (1)
Hikvision/DS-2CD Series https://www.hikvision.com/en/support/download/firmware/security-firmware-download/
Published Jul 22, 2026
Tracked Since Jul 22, 2026