Junglewise Threat Intelligence

CVE-2021-36260: Hikvision Improper Input Validation

CVE-2021-36260 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-01-10

Vendors: Hikvision.

Executive brief

A command injection vulnerability exists in the web server of various Hikvision products due to insufficient input validation. Unauthenticated remote attackers can exploit this by sending specially crafted messages to execute arbitrary OS commands.

Affected products

  • Hikvision IP Camera Firmware Build 210702 and earlier

Timeline

  • 2022-01-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-01-10: disclosed