Executive brief
Hikvision intercom systems store an immutable factory value on their main cards that is used to validate legitimate access cards. This vulnerability allows attackers to forge valid access cards by obtaining or predicting this factory value, potentially granting unauthorized users the ability to issue additional cards and gain physical access to secured areas protected by these intercoms.
Technical details
The vulnerability exists in Hikvision intercom products that rely on an immutable factory value embedded in their main card for access control validation. An attacker who obtains this factory value—either through local network reconnaissance or physical interaction with a device—can forge legitimate main cards and bypass the card validation mechanism. The flaw allows an attacker to issue additional access cards and gain unauthorized permission escalation within the intercom system. No authentication or remote attack vector is required if the attacker has local network or physical access. Patch availability has not been confirmed in the provided advisory details.
Affected products
- Hikvision Intercom <UNKNOWN>
Timeline
- 2026-09-10: disclosed