Junglewise Threat Intelligence

CVE-2025-66177: Hikvision NVR/DVR/IPC buffer overflow in Search and Discovery feature

CVE-2025-66177 · Severity: high · CVSS 8.8 · Published 2026-01-13

Vendors: Hikvision.

Executive brief

A security vulnerability exists in the device discovery feature of various Hikvision video recording and camera products. An attacker on the same local network can send malicious data packets to cause the device to crash or malfunction. This could lead to a loss of video surveillance capabilities and potential unauthorized access to the device.

Technical details

A stack-based buffer overflow (CWE-121) exists in the Search and Discovery feature of multiple Hikvision product lines, including NVR, DVR, CVR, and IPC models. The vulnerability is triggered when the device processes specially crafted network packets sent over the local area network (LAN). An unauthenticated attacker with adjacent network access can exploit this flaw to cause a denial-of-service (malfunction) or potentially achieve remote code execution. Hikvision has released firmware updates to address this issue; affected devices are those with build dates prior to August 7, 2025 (250807).

Affected products

  • Hikvision NVR/DVR/CVR/IPC models Build date before 250807

Timeline

  • 2026-01-12: disclosed
  • 2026-01-13: advisory

References