RCE Vulnerability in Hikvision Cameras (CVE-2021-36260)
Cybersecurity and Infrastructure Security Agency sent this bulletin at 09/28/2021 12:32 PM EDT
You are subscribed to no topic for Cybersecurity and Infrastructure Security Agency. This information has recently been updated, and is now available.
09/28/2021 11:43 AM EDT
Original release date: September 28, 2021
Hikvision has released updates to mitigate a command injection vulnerability—CVE-2021-36260—in Hikvision cameras that use a web server service. A remote attacker could exploit this vulnerability to take control of an affected device.
CISA encourages users and administrators to review Hikvision’s Security Advisory HSRC-202109-01 and apply the latest firmware updates. See security researcher Watchful IP’s technical blogpost for more information.
This product is provided subject to this Notification and this Privacy & Use policy.