Junglewise Threat Intelligence

CVE-2026-61390: Hikvision Cameras heap buffer overflow in DS-2CD and DS-2DE series

CVE-2026-61390 · Severity: high · CVSS 7.7 · Published 2026-07-22

Technologies: Hikvision DS-2DE Series, Hikvision DS-2CD Series. Vendors: Hikvision.

Executive brief

A security vulnerability has been identified in certain Hikvision security cameras that could allow an unauthorized person to disrupt the device's operation. By sending specifically designed network traffic, an attacker can cause the camera to malfunction or crash, potentially leading to a loss of video surveillance and security monitoring. This issue affects the DS-2CD and DS-2DE series of cameras, which are widely used for physical security and facility oversight.

Technical details

A heap buffer overflow vulnerability exists in the firmware of certain Hikvision cameras, specifically within the DS-2CD and DS-2DE product lines. The flaw is triggered when the device processes specially crafted network packets sent by an unauthenticated attacker. While the attack complexity is rated as high, a successful exploit can lead to a device crash (denial of service) or potentially broader system instability. The vulnerability is reachable over the network without requiring user interaction or prior authentication. Hikvision has released a security advisory directing users to their firmware download portal for updates.

Affected products

  • Hikvision DS-2CD Series
  • Hikvision DS-2DE Series

Timeline

  • 2026-07-22: disclosed
  • 2026-07-22: advisory

References

Related threats