Executive brief
A security vulnerability has been identified in several Hikvision access control terminals, which are devices used for physical security, facial recognition, and building entry. An attacker on the same local network could send a malicious data packet to the device, causing it to crash or potentially allowing them to take control of the system. This could lead to a disruption of security operations or unauthorized access to sensitive areas and data.
Technical details
A stack-based buffer overflow (CWE-121) exists in the SADP XML parsing functionality within the 'hicore' binary of Hikvision Access Control Products. The vulnerability is located in the 'multicast_thr_sadp_capture' thread, specifically within the custom XML parser used to interpret SADP payloads received via multicast UDP port 37020. An unauthenticated attacker on the same local area network (LAN) can send a specially crafted XML packet to trigger the overflow. Successful exploitation can lead to a device malfunction (denial of service) or remote code execution (RCE). Hikvision has released firmware updates for affected models to address this flaw.
Affected products
- Hikvision DS-K1T331 Below V3.7.80
- Hikvision DS-K1T341A/K1T341B Below V3.7.80
- Hikvision DS-K1T671/K5671 Below V3.7.80
- Hikvision DS-K1T672 Below V3.7.80
- Hikvision DS-K1T680 Below V3.7.80
- Hikvision DS-K1T981 Below V3.7.80
- Hikvision DS-K1T341C Below V3.3.180
- Hikvision DS-K1T670/K1T673 Below V4.48.0
- Hikvision DS-K1T8003/8004 Below V1.4.21
- Hikvision DS-K1T804A Below V1.4.22
- Hikvision DS-K1T804B Below V1.4.23
- Hikvision DS-K1T201A/K1T105A Below V1.3.65
Timeline
- 2025-01-13: advisory: Initial CVE publication date
- 2026-03-18: other: Detailed Talos vulnerability report published