Page 1 of 1

Hikvision cameras have a critical remote code execution vulnerability

Posted: Mon Sep 20, 2021 10:02 pm
by Thixotropic
FYI.......

The majority of the recent camera product ranges of Hikvision cameras are susceptible to a critical remote unauthenticated code execution vulnerability even with latest firmware (as of 21 June 2021). Some older models are affected also as far back as at least 2016. Some NVRs are also affected, though this is less widespread.

More details from Hikvision:
https://www.hikvision.com/en/support/cy ... -products/

This is being tracked as CVE-2021-36260

Summary:
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability to launch a command injection attack by sending some messages with malicious commands.

Re: Hikvision cameras have a critical remote code execution vulnerability

Posted: Tue Sep 21, 2021 2:48 am
by HeneryH
You should consider ALL security cameras to have vulnerabilities capable of stealing all of your money along with your spouse. Protect your system accordingly.

Re: Hikvision cameras have a critical remote code execution vulnerability

Posted: Fri Sep 24, 2021 3:25 pm
by TimG
Yup, connect them only to your second NIC :?