ZeroHour

CVE-2021-36260

KEV PoC ×3mass1

Unauthenticated Command Injection in Hikvision Device Web Server

CISA: Hikvision Improper Input Validation

CVSS 3.1
9.8 critical
EPSS
100%p100
Published
()
KEV added
AI analysis

CVE-2021-36260 is a command injection flaw (CWE-78) in the web server embedded in a wide range of Hikvision security camera and related devices, caused by insufficient input validation. An attacker triggers it by sending a crafted HTTP request to the device's web management interface, allowing commands to be executed on the device without authentication. Successful exploitation grants unauthenticated remote code execution on the camera or recorder, letting an attacker take control of the device, pivot into the surrounding network, or use the devices as a botnet platform. Any Hikvision device running the affected web server firmware is at risk, which includes cameras, recorders, and other surveillance hardware deployed in homes, businesses, and government facilities. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-01-10 and carries a 99.9% EPSS probability of exploitation within 30 days, while no public proof-of-concept code is cataloged in the provided data and no CVSS score has been issued yet.

What to do: Apply firmware updates issued by Hikvision per the vendor's instructions, as required by CISA's KEV listing for this vulnerability. Restrict the device web management interface to trusted networks or VPN access and avoid direct internet exposure. Review web server logs for anomalous HTTP requests to the device interface and signs of command execution, and prioritize internet-facing devices for patching first.

Affected
Hikvision Embedded web server of Hikvision security cameras and related surveillance devices
Estimated exposure
massmillions of installed devices, with roughly hundreds of thousands to over a million Hikvision web interfaces exposed to the internet — Hikvision is the world's largest video surveillance vendor with tens of millions of devices deployed, and public internet-wide scans have repeatedly counted hundreds of thousands to millions of exposed Hikvision device web interfaces, many…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability to launch a command injection attack by sending some messages with malicious commands.

CISA Known Exploited Vulnerability
Affected
Hikvision Security cameras web server
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
hikvision
Products
ds-2cd2026g2-iu\/sl firmware, ds-2cd2046g2-iu\/sl firmware, ds-2cd2066g2-i\(u\) firmware, ds-2cd2066g2-iu\/sl firmware, ds-2cd2086g2-i\(u\) firmware, ds-2cd2086g2-iu\/sl firmware, ds-2cd2166g2-i\(su\) firmware, ds-2cd2186g2-i\(su\) firmware, ds-2cd2186g2-isu firmware, ds-2cd2326g2-isu\/sl firmware, ds-2cd2346g2-isu\/sl firmware, ds-2cd2366g2-i\(u\) firmware
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies

Fortinet researchers documented Evooo1Bot, a new Mirai-derived Linux botnet active since July 2026 that exploits known edge-device flaws to build SOCKS5 proxy networks.

Fortinet FortiGuard Labs identified Evooo1Bot, a previously undocumented Linux botnet built on the leaked Mirai source code, active in the wild since July 2026 and targeting internet-facing edge devices. It exploits numerous known CVEs in routers and devices from D-Link, Tenda, Telesquare, Zyxel, Hikvision, Atlassian Confluence, WSO2, TP-Link, NETGEAR, and others, delivering a bot binary via a wget.sh loader from 91.92.40.118 that clears bash history. The bot offers encrypted C2 on port 443, SSH brute-force scanning, credential sniffing, DDoS over DNS/TCP/UDP, an HTTP exploit dispatcher, and converts infected hosts into SOCKS5 proxies for anonymizing follow-on operations.

The Hacker News · 29d agoMalware in the wildCVE-2007-3010CVE-2016-6277CVE-2018-14558+15 CVEs