Junglewise Threat Intelligence

CVE-2026-61391: Hikvision DS-2CD and DS-2DE Series stack-based buffer overflow

CVE-2026-61391 · Severity: high · CVSS 7.2 · Published 2026-07-22

Technologies: Hikvision DS-2DE Series, Hikvision DS-2CD Series. Vendors: Hikvision.

Executive brief

A security vulnerability has been identified in certain Hikvision network cameras used for video surveillance. An authorized user with high-level permissions could exploit this flaw to cause the camera to malfunction or crash by sending specifically designed network traffic. This could lead to a loss of video monitoring capabilities and potential disruption of security operations.

Technical details

A stack-based buffer overflow vulnerability exists in the firmware of several Hikvision camera series, including the DS-2CD and DS-2DE lines. The flaw is triggered when the device processes specially crafted network packets. While the attack can be carried out over the network, it requires the attacker to be authenticated with high-level privileges (PR:H). Successful exploitation can lead to a denial-of-service condition (device malfunction) or potentially broader system compromise. Hikvision has released a security advisory directing users to their firmware download page for updates.

Affected products

  • Hikvision DS-2CD Series
  • Hikvision DS-2DE Series

Timeline

  • 2026-07-22: advisory: Initial disclosure by Hikvision and NVD publication

References

Related threats