CVE-2021-36260
Severity CVSS v4.0:
Pending analysis
Type:
CWE-78
OS Command Injections
Publication date:
22/09/2021
Last modified:
02/04/2025
Description
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability to launch a command injection attack by sending some messages with malicious commands.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
9.30
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:hikvision:ds-2cd2026g2-iu\/sl_firmware:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:hikvision:ds-2cd2026g2-iu\/sl:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:hikvision:ds-2cd2046g2-iu\/sl_firmware:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:hikvision:ds-2cd2046g2-iu\/sl:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:hikvision:ds-2cd2066g2-i\(u\)_firmware:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:hikvision:ds-2cd2066g2-i\(u\):-:*:*:*:*:*:*:* | ||
cpe:2.3:o:hikvision:ds-2cd2066g2-iu\/sl_firmware:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:hikvision:ds-2cd2066g2-iu\/sl:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:hikvision:ds-2cd2086g2-i\(u\)_firmware:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:hikvision:ds-2cd2086g2-i\(u\):-:*:*:*:*:*:*:* | ||
cpe:2.3:o:hikvision:ds-2cd2086g2-iu\/sl_firmware:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:hikvision:ds-2cd2086g2-iu\/sl:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:hikvision:ds-2cd2166g2-i\(su\)_firmware:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:hikvision:ds-2cd2166g2-i\(su\):-:*:*:*:*:*:*:* | ||
cpe:2.3:o:hikvision:ds-2cd2186g2-i\(su\)_firmware:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://packetstormsecurity.com/files/164603/Hikvision-Web-Server-Build-210702-Command-Injection.html
- http://packetstormsecurity.com/files/166167/Hikvision-IP-Camera-Unauthenticated-Command-Injection.html
- https://therecord.media/experts-warn-of-widespread-exploitation-involving-hikvision-cameras/
- https://www.cyfirma.com/wp-content/uploads/2022/08/HikvisionSurveillanceCamerasVulnerabilities.pdf
- https://www.hikvision.com/en/support/cybersecurity/security-advisory/security-notification-command-injection-vulnerability-in-some-hikvision-products/
- http://packetstormsecurity.com/files/164603/Hikvision-Web-Server-Build-210702-Command-Injection.html
- http://packetstormsecurity.com/files/166167/Hikvision-IP-Camera-Unauthenticated-Command-Injection.html
- https://therecord.media/experts-warn-of-widespread-exploitation-involving-hikvision-cameras/
- https://www.cyfirma.com/wp-content/uploads/2022/08/HikvisionSurveillanceCamerasVulnerabilities.pdf
- https://www.hikvision.com/en/support/cybersecurity/security-advisory/security-notification-command-injection-vulnerability-in-some-hikvision-products/