>> All posts

CVE-2017-7921: Hikvision camera authentication bypass, actively exploited

The short version: A range of Hikvision IP cameras carry an improper-authentication flaw (CVE-2017-7921) that lets an unauthenticated attacker bypass authentication, escalate privileges, and retrieve sensitive information — including device configuration and credentials. It's an old bug that's still everywhere, it's in CISA's KEV catalog, and exploitation activity is near-certain. Confirm your exposure and replace or isolate affected cameras. Steady hands — but move.

At a glance

FactDetail
Our severity takeHigh — unauthenticated, KEV-listed, near-certain exploitation
CVSS v3.1 (NVD)9.8 — Critical · AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2 (NVD)7.5 — High
EPSS~99.99% · 99th percentile (2026-07-17)
In CISA KEV?Yes — remediate by 2026-03-26
Known exploited?Yes — listed in CISA KEV
Vulnerability typeCWE-287 improper authentication → privilege escalation / sensitive information disclosure
Requires authenticated session?No — pre-authentication
AffectedSpecific Hikvision camera series and firmware ranges — including DS-2CD2xx2F-I, DS-2CD2xx0F-I, DS-2CD2xx2FWD, DS-2CD4x2xFWD, DS-2CD4xx5, DS-2DFx, and DS-2CD63xx builds
Fixed inUpdated firmware from Hikvision (see the vendor security notification)

What you need to know

The affected cameras don't correctly authenticate requests. By supplying a crafted authentication parameter, an unauthenticated attacker reaches endpoints that should require a valid login — enough to escalate privileges and read sensitive data off the device, including configuration and user credentials. With those credentials, an attacker gets full control of the camera and a foothold on the network segment it sits on.

Why it's top-of-queue despite its age:

  • It's pre-authentication and trivially reachable. Cameras are routinely exposed to the internet for remote viewing.
  • It leaks credentials. Recovering device credentials turns a camera bug into broader access.
  • It's still being exploited. CISA added it to KEV in 2026, and EPSS puts exploitation probability at essentially certain — a reminder that unpatched cameras never aged out of attackers' toolkits.

How serious we see it

Critical.

An unauthenticated authentication bypass that yields credentials on an internet-facing device, KEV-listed with near-certain exploitation, is top-of-queue. The bounded, reassuring part is that specific camera series and firmware builds are affected, updated firmware exists, and you can determine exposure quickly. The practical catch with cameras is inventory — they're easy to forget, which is exactly why they linger.

Recommendations

Straight from Hikvision's security notification and CISA:

  1. Update firmware now. Apply the fixed firmware Hikvision published for the affected series.
  2. Get cameras off the public internet. Put them behind a VPN or restrict management to trusted networks; never expose the web interface directly.
  3. Rotate credentials. Assume device credentials may have leaked; change them and any reused elsewhere.
  4. Replace end-of-life devices. Where no fixed firmware exists for your model, retire it.
  5. Confirm your exposure first. Verify whether any affected Hikvision camera is reachable from the internet.

How BreachRisk sees it

BreachRisk discovers internet-facing Hikvision cameras in your external footprint the way an attacker would, fingerprints the device, and flags exposure tied to this KEV-listed CVE — surfaced at the top of your results because it's actively exploited. Cameras are the classic forgotten asset, and an outside-in view is exactly how they get found before someone else finds them.

That continuous, attacker's-eye view means an exposed camera is on your radar as a specific, prioritized finding rather than an unmanaged device quietly sitting on the internet.

References

See your cyber risk, proven.