Junglewise Threat Intelligence

CVE-2026-3828: Hikvision Switches remote command execution due to insufficient input validation

CVE-2026-3828 · Severity: high · CVSS 7.2 · Published 2026-05-09

Vendors: Hikvision.

Executive brief

Certain Hikvision network switches are vulnerable to a security flaw that allows an authorized user to take full control of the device. By sending specially crafted data to the switch, an attacker with valid login credentials can execute unauthorized commands. This could lead to a complete disruption of network traffic, unauthorized access to sensitive data passing through the switch, or a total system takeover.

Technical details

A remote command execution vulnerability (CWE-78) exists in several Hikvision switch models due to insufficient input validation. An attacker with high-privileged credentials can exploit this by sending crafted network packets containing malicious OS commands to the device. Successful exploitation allows for arbitrary command execution with the privileges of the underlying operating system. The affected products (DS-3E1310P-SI, DS-3E1318P-SI, and DS-3E1326P-SI) were discontinued in December 2023, but patches were released for specific firmware versions to address the flaw.

Affected products

  • Hikvision DS-3E1310P-SI Versions below V1.2.4_210623 (including V1.2.4_210623)
  • Hikvision DS-3E1318P-SI Versions below V1.2.0_210823 (including V1.2.0_210823)
  • Hikvision DS-3E1326P-SI Versions below V1.2.0_210823 (including V1.2.0_210823)

Timeline

  • 2026-05-09: disclosed
  • 2026-05-09: advisory

References