Junglewise Threat Intelligence

CVE-2026-57600: Hikvision Camera Series improper input validation in firmware

CVE-2026-57600 · Severity: high · CVSS 7.5 · Published 2026-07-22

Technologies: Hikvision DS-2DE Series, Hikvision DS-2CD Series. Vendors: Hikvision.

Executive brief

A security vulnerability has been identified in the firmware of several Hikvision camera series, which are widely used for physical security and surveillance. An unauthorized person could remotely access the camera over the network and retrieve sensitive information without needing a password. This could lead to the exposure of private data or provide a foothold for further attacks on the security network.

Technical details

An information disclosure vulnerability exists in the firmware of Hikvision DS-2CD, DS-2DE, DS-2DP, and DS-2TD series cameras due to insufficient validation of input parameters. The flaw allows a remote, unauthenticated attacker to send crafted requests to the device over the network to retrieve partial sensitive data. The vulnerability is rated with a CVSS base score of 7.5, reflecting high confidentiality impact with no requirement for privileges or user interaction. Users are advised to visit the Hikvision security firmware download page for updates.

Affected products

  • Hikvision DS-2CD Series
  • Hikvision DS-2DE Series
  • Hikvision DS-2DP Series
  • Hikvision DS-2TD Series

Timeline

  • 2026-07-22: disclosed
  • 2026-07-22: advisory

References

Related threats