CVE-2021-36260

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
22/09/2021
Last modified:
02/04/2025

Description

A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability to launch a command injection attack by sending some messages with malicious commands.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:hikvision:ds-2cd2026g2-iu\/sl_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-2cd2026g2-iu\/sl:-:*:*:*:*:*:*:*
cpe:2.3:o:hikvision:ds-2cd2046g2-iu\/sl_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-2cd2046g2-iu\/sl:-:*:*:*:*:*:*:*
cpe:2.3:o:hikvision:ds-2cd2066g2-i\(u\)_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-2cd2066g2-i\(u\):-:*:*:*:*:*:*:*
cpe:2.3:o:hikvision:ds-2cd2066g2-iu\/sl_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-2cd2066g2-iu\/sl:-:*:*:*:*:*:*:*
cpe:2.3:o:hikvision:ds-2cd2086g2-i\(u\)_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-2cd2086g2-i\(u\):-:*:*:*:*:*:*:*
cpe:2.3:o:hikvision:ds-2cd2086g2-iu\/sl_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-2cd2086g2-iu\/sl:-:*:*:*:*:*:*:*
cpe:2.3:o:hikvision:ds-2cd2166g2-i\(su\)_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-2cd2166g2-i\(su\):-:*:*:*:*:*:*:*
cpe:2.3:o:hikvision:ds-2cd2186g2-i\(su\)_firmware:-:*:*:*:*:*:*:*