CVE-2021-36260
Description
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability to launch a command injection attack by sending some messages with malicious commands.
Summary dbcve.org
A command injection vulnerability exists in the web server component of Hikvision camera products. Due to insufficient input validation, remote attackers can send specially crafted HTTP requests containing malicious commands that get executed with elevated privileges on the underlying operating system.
Mitigation
Update affected Hikvision devices to the latest firmware version that includes the security patch. If immediate patching is not feasible, restrict network access to the device web interfaces using firewalls or VLANs to prevent unauthorized exploitation.