CRITICAL

CVE-2021-36260

Hikvision Ds 2cd2026g2 Iu\/sl Firmware 2021-09-22 CVSS v3.1
CVSS
9.8
KEV

Description

A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability to launch a command injection attack by sending some messages with malicious commands.

Summary dbcve.org

A command injection vulnerability exists in the web server component of Hikvision camera products. Due to insufficient input validation, remote attackers can send specially crafted HTTP requests containing malicious commands that get executed with elevated privileges on the underlying operating system.

Mitigation

Update affected Hikvision devices to the latest firmware version that includes the security patch. If immediate patching is not feasible, restrict network access to the device web interfaces using firewalls or VLANs to prevent unauthorized exploitation.

Proof of Concept

Weakness (CWE)

CWE-78 OS Command Injection

EPSS Score

99.87%
Probability of exploitation in next 30 days
100th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE