CVE-2017-7921: Hikvision camera authentication bypass, actively exploited
The short version: A range of Hikvision IP cameras carry an improper-authentication flaw (CVE-2017-7921) that lets an unauthenticated attacker bypass authentication, escalate privileges, and retrieve sensitive information — including device configuration and credentials. It's an old bug that's still everywhere, it's in CISA's KEV catalog, and exploitation activity is near-certain. Confirm your exposure and replace or isolate affected cameras. Steady hands — but move.
At a glance
| Fact | Detail |
|---|---|
| Our severity take | High — unauthenticated, KEV-listed, near-certain exploitation |
| CVSS v3.1 (NVD) | 9.8 — Critical · AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVSS v2 (NVD) | 7.5 — High |
| EPSS | ~99.99% · 99th percentile (2026-07-17) |
| In CISA KEV? | Yes — remediate by 2026-03-26 |
| Known exploited? | Yes — listed in CISA KEV |
| Vulnerability type | CWE-287 improper authentication → privilege escalation / sensitive information disclosure |
| Requires authenticated session? | No — pre-authentication |
| Affected | Specific Hikvision camera series and firmware ranges — including DS-2CD2xx2F-I, DS-2CD2xx0F-I, DS-2CD2xx2FWD, DS-2CD4x2xFWD, DS-2CD4xx5, DS-2DFx, and DS-2CD63xx builds |
| Fixed in | Updated firmware from Hikvision (see the vendor security notification) |
What you need to know
The affected cameras don't correctly authenticate requests. By supplying a crafted authentication parameter, an unauthenticated attacker reaches endpoints that should require a valid login — enough to escalate privileges and read sensitive data off the device, including configuration and user credentials. With those credentials, an attacker gets full control of the camera and a foothold on the network segment it sits on.
Why it's top-of-queue despite its age:
- It's pre-authentication and trivially reachable. Cameras are routinely exposed to the internet for remote viewing.
- It leaks credentials. Recovering device credentials turns a camera bug into broader access.
- It's still being exploited. CISA added it to KEV in 2026, and EPSS puts exploitation probability at essentially certain — a reminder that unpatched cameras never aged out of attackers' toolkits.
How serious we see it
Critical.
An unauthenticated authentication bypass that yields credentials on an internet-facing device, KEV-listed with near-certain exploitation, is top-of-queue. The bounded, reassuring part is that specific camera series and firmware builds are affected, updated firmware exists, and you can determine exposure quickly. The practical catch with cameras is inventory — they're easy to forget, which is exactly why they linger.
Recommendations
Straight from Hikvision's security notification and CISA:
- Update firmware now. Apply the fixed firmware Hikvision published for the affected series.
- Get cameras off the public internet. Put them behind a VPN or restrict management to trusted networks; never expose the web interface directly.
- Rotate credentials. Assume device credentials may have leaked; change them and any reused elsewhere.
- Replace end-of-life devices. Where no fixed firmware exists for your model, retire it.
- Confirm your exposure first. Verify whether any affected Hikvision camera is reachable from the internet.
How BreachRisk sees it
BreachRisk discovers internet-facing Hikvision cameras in your external footprint the way an attacker would, fingerprints the device, and flags exposure tied to this KEV-listed CVE — surfaced at the top of your results because it's actively exploited. Cameras are the classic forgotten asset, and an outside-in view is exactly how they get found before someone else finds them.
That continuous, attacker's-eye view means an exposed camera is on your radar as a specific, prioritized finding rather than an unmanaged device quietly sitting on the internet.