Junglewise Threat Intelligence

CVE-2017-7921: Hikvision IP Cameras improper authentication

CVE-2017-7921 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2026-03-05

Technologies: Apple Multiple Products. Vendors: Hikvision, Apple.

Executive brief

Multiple Hikvision IP cameras and surveillance products contain a critical security flaw that allows unauthorized users to bypass authentication. This vulnerability enables an attacker to gain full administrative control over the camera system, potentially allowing them to view private video feeds, modify settings, or disable security monitoring. This issue has been actively exploited in the wild, posing a significant risk to physical security and data privacy.

Technical details

An improper authentication vulnerability (CWE-287) exists in several Hikvision IP camera firmware versions. The flaw occurs because the application fails to adequately validate user identity, allowing a remote, unauthenticated attacker to bypass security checks via the network. By exploiting this, an attacker can escalate their privileges to an administrative level, granting full access to the device's configuration and data. This vulnerability is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, confirming active real-world exploitation. Users should apply firmware updates provided by the vendor to mitigate this risk.

Affected products

  • Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530
  • Hikvision DS-2CD2xx0F-I Series V5.2.0 build 140721 to V5.4.0 Build 160401
  • Hikvision DS-2CD2xx2FWD Series V5.3.1 build 150410 to V5.4.4 Build 161125
  • Hikvision DS-2CD4x2xFWD Series V5.2.0 build 140721 to V5.4.0 Build 160414
  • Hikvision DS-2CD4xx5 Series V5.2.0 build 140721 to V5.4.0 Build 160421
  • Hikvision DS-2DFx Series V5.2.0 build 140805 to V5.4.5 Build 160928
  • Hikvision DS-2CD63xx Series V5.0.9 build 140305 to V5.3.5 Build 160106

Timeline

  • 2017-03-14: disclosed: Initial vendor notification/advisory date
  • 2026-03-05: kev added: Added to CISA Known Exploited Vulnerabilities catalog

Related threats