Junglewise Threat Intelligence

CVE-2026-61392: Hikvision DS-2CD and DS-2DE Series information disclosure

CVE-2026-61392 · Severity: medium · CVSS 5.3 · Published 2026-07-22

Technologies: Hikvision DS-2DE Series, Hikvision DS-2CD Series. Vendors: Hikvision.

Executive brief

A security vulnerability has been identified in several Hikvision camera models used for professional video surveillance. This flaw allows an unauthorized person to remotely access fragments of the camera's internal memory over the network. While the attacker cannot take full control of the device, they may be able to view sensitive technical data that could assist in further attacks.

Technical details

An information disclosure vulnerability exists in the firmware of Hikvision DS-2CD and DS-2DE series cameras. The flaw allows a remote, unauthenticated attacker to read portions of the device's memory via the network. This is likely due to improper bounds checking or insufficient validation of requests for memory-resident data. Successful exploitation results in the leakage of partial system information, though the specific nature of the data (e.g., credentials, configuration, or session tokens) is not detailed in the advisory. Users are advised to check the Hikvision security portal for firmware updates.

Affected products

  • Hikvision DS-2CD Series
  • Hikvision DS-2DE Series

Timeline

  • 2026-07-22: disclosed
  • 2026-07-22: advisory

References

Related threats