Junglewise Threat Intelligence

CVE-2026-16843: Hikvision Wireless Access Points authenticated command execution

CVE-2026-16843 · Severity: high · CVSS 7.2 · Published 2026-07-31

Executive brief

Several Hikvision wireless access points are affected by a security flaw that allows an authorized user to execute unauthorized commands on the device. These devices are used to provide Wi-Fi connectivity in business and industrial environments. If exploited, an attacker with administrative credentials could take full control of the network hardware, potentially leading to data interception or network downtime.

Technical details

A command injection vulnerability exists in multiple Hikvision Wireless Access Point models due to insufficient validation of user-supplied input. An attacker with high-privileged (authenticated) network access can exploit this by sending specially crafted packets to the device's management interface. Successful exploitation allows for arbitrary command execution on the underlying operating system. The vulnerability affects various DS-3WAP and DS-3WG series models running firmware version V1.1.6601 build251223 and earlier. Users are advised to update to the latest firmware versions provided by the vendor.

Affected products

  • Hikvision DS-3WAP521-SI V1.1.6601 build251223 and earlier
  • Hikvision DS-3WAP522-SI V1.1.6601 build251223 and earlier
  • Hikvision DS-3WAP621E-SI V1.1.6601 build251223 and earlier
  • Hikvision DS-3WAP622E-SI V1.1.6601 build251223 and earlier
  • Hikvision DS-3WAP623E-SI V1.1.6601 build251223 and earlier
  • Hikvision DS-3WAP622G-SI V1.1.6601 build251223 and earlier
  • Hikvision DS-3WG105G-SI V1.1.6601 build251223 and earlier
  • Hikvision DS-3WG105GP-SI V1.1.6601 build251223 and earlier
  • Hikvision DS-3WG210GP-SI V1.1.6601 build251223 and earlier
  • Hikvision DS-3WG507G-SI V1.1.6601 build251223 and earlier

Timeline

  • 2026-07-31: disclosed
  • 2026-07-31: advisory

References