CVE-2021-36260
hikvision ds-2cd2026g2-iu/sl firmware, hikvision ds-2cd2046g2-iu/sl firmware, hikvision ds-2cd2066g2-i(u) firmware
Published 22 Sept 2021 · updated 17 Jun 2026 · Analyzed
9.8 Critical · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 10 Jan 2022, with a remediation deadline of 24 Jan 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability to launch a command injection attack by sending some messages with malicious commands.
References
- packetstormsecurity.com/files/164603/Hikvision-Web-Server-Build-210702-Command-Injection.html · Exploit, Third Party Advisory, VDB Entry
- packetstormsecurity.com/files/166167/Hikvision-IP-Camera-Unauthenticated-Command-Injection.html · Exploit, Third Party Advisory, VDB Entry
- therecord.media/experts-warn-of-widespread-exploitation-involving-hikvision-cameras/ · Third Party Advisory
- www.cyfirma.com/wp-content/uploads/2022/08/HikvisionSurveillanceCamerasVulnerabilities.pdf · Broken Link, Exploit, Third Party Advisory
- www.hikvision.com/en/support/cybersecurity/security-advisory/security-notification-command-injection-vulnerability-in-some-hikvision-products/ · Vendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-36260 · US Government Resource