PatchSiren

Hikvision CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Hikvision CVE published 2026-07-31

CVE-2026-16843

Authenticated command execution vulnerability exists in some Hikvision Wireless Access Points due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution. This high-severity vulnerability, with a CVSS score of 7.2, allows attackers to execute commands on aff [truncated]

HIGH Hikvision CVE published 2026-07-22

CVE-2026-61391

CVE-2026-61391 is a stack-based buffer overflow vulnerability in some Hikvision cameras. The vulnerability may allow authenticated attackers to cause device malfunction by sending specially crafted packets. The CVE record was published on 2026-07-22T12:18:18.247Z and has not been modified since then. Affected product deployments should be reviewed for potential exposure, and owners should assess the impac [truncated]

HIGH Hikvision CVE published 2026-07-22

CVE-2026-61390

CVE-2026-61390 is a high-severity vulnerability in some Hikvision cameras, allowing unauthenticated attackers to cause device malfunction via specially crafted packets. The vulnerability has a CVSS score of 7.7 and is classified as HIGH. The CVE record was published on 2026-07-22T12:18:18.137Z and was last modified on 2026-07-22T20:50:36.493Z. Organizations should review their deployments for affected Hik [truncated]

HIGH Hikvision CVE published 2026-07-22

CVE-2026-57600

CVE-2026-57600 is a HIGH severity vulnerability in Hikvision camera firmware, allowing unauthenticated attackers to retrieve partial sensitive data due to insufficient validation of input parameters. The vulnerability affects Hikvision cameras and has a CVSS score of 7.5. Users should review firmware updates and validate input parameters. The CVE record was published on 2026-07-22T12:18:16.883Z and has no [truncated]

MEDIUM Hikvision CVE published 2026-07-22

CVE-2026-57599

CVE-2026-57599 is a medium-severity privilege escalation vulnerability in some Hikvision cameras. The vulnerability exists due to incorrect permission allocation in the device program, allowing attackers to escalate privileges and gain full control of the device after authenticating via SSH. This type of vulnerability can have significant operational impacts, as it could allow attackers to gain unauthoriz [truncated]

HIGH Hikvision CVE published 2026-05-09

CVE-2026-3828

CVE-2026-3828 is an authenticated remote command execution vulnerability affecting some Hikvision switch products that have been discontinued since December 2023. According to the vendor advisory and NVD entry, a valid user can send crafted packets with malicious commands and obtain arbitrary command execution on affected devices. Because the issue impacts network-facing infrastructure and can affect conf [truncated]

MEDIUM Hikvision CVE published 2026-05-09

CVE-2026-1749

CVE-2026-1749 is an access control vulnerability in some HikCentral Professional versions that may let an unauthenticated user obtain admin permission. NVD lists the issue with a CVSS 3.1 vector of AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N, indicating network reachability and potentially high confidentiality impact if the flaw is reachable in a deployed environment.

Known exploited Hikvision CVE published 2026-03-05

CVE-2017-7921

CVE-2017-7921 is a Hikvision improper authentication vulnerability affecting multiple products and is listed in CISA’s Known Exploited Vulnerabilities catalog. Because CISA has added it to KEV, defenders should treat it as an actively exploited issue and prioritize vendor-guided mitigation or replacement where mitigation is not available. The supplied source set points readers to Hikvision’s special notic [truncated]

HIGH Hikvision CVE published 2026-01-13

CVE-2025-66177

A buffer overflow vulnerability exists in the device Search and Discovery feature of Hikvision NVR/DVR/CVR/IPC models. If exploited, an attacker on the same local area network (LAN) could cause the device to malfunction by sending specially crafted packets to an unpatched device. This issue has a CVSS score of 8.8 and is classified as HIGH severity. Organizations should prioritize patching to prevent pote [truncated]

HIGH Hikvision CVE published 2026-01-13

CVE-2025-66176

A buffer overflow vulnerability exists in the device Search and Discovery feature of Hikvision Access Control Products. If exploited, an attacker on the same local area network (LAN) could cause the device to malfunction by sending specially crafted packets to an unpatched device. This issue has a CVSS score of 8.8 and is classified as HIGH severity. Organizations should prioritize patching affected devic [truncated]

Known exploited Hikvision CVE published 2022-01-10

CVE-2021-36260

CVE-2021-36260 is a Hikvision security camera web server vulnerability described as improper input validation. CISA lists it in the Known Exploited Vulnerabilities catalog, which means defenders should treat it as an active-risk issue and prioritize remediation using vendor guidance.