Executive brief
A security flaw exists in certain Hikvision DS-2CD series cameras, which are widely used for professional video surveillance. An attacker who already has limited access to the camera's command-line interface can exploit this flaw to gain full administrative control. This could allow an unauthorized party to disable security monitoring, access private video feeds, or use the device as a foothold to attack other parts of the corporate network.
Technical details
A privilege escalation vulnerability exists in the firmware of Hikvision DS-2CD series cameras due to incorrect permission allocation within the device program. The flaw is reachable via the SSH interface; an attacker must first possess valid credentials to authenticate to the device. Once authenticated, the attacker can exploit the improper access controls to elevate their privileges to a higher level, potentially gaining root or full administrative access. This allows for complete compromise of the device's integrity, confidentiality, and availability. Hikvision has released a security advisory directing users to updated firmware versions to mitigate this risk.
Affected products
- Hikvision DS-2CD Series Cameras Multiple versions (refer to vendor advisory)
Timeline
- 2026-07-22: advisory: Initial disclosure by Hikvision and NVD publication