>> All posts

CVE-2021-36260: Hikvision unauthenticated command injection, actively exploited

The short version: Many Hikvision products have a command-injection flaw in their web server (CVE-2021-36260) that lets an unauthenticated attacker run arbitrary commands on the device by sending a crafted message. It's in CISA's KEV catalog, it's been widely exploited, and EPSS puts exploitation near-certain. Update firmware and get these devices off the open internet. Steady hands — but move.

At a glance

FactDetail
Our severity takeHigh — unauthenticated RCE, widely exploited
CVSS v3.1 (NVD)9.8 — Critical · AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2 (NVD)9.3 — High
EPSS~99.87% · 99th percentile (2026-07-17)
In CISA KEV?Yes — remediate by 2022-01-24
Known exploited?Yes — widespread exploitation reported; listed in CISA KEV
Vulnerability typeCWE-78 OS command injection → unauthenticated remote code execution
Requires authenticated session?No — pre-authentication
AffectedNumerous Hikvision products with the affected web-server firmware (see the vendor security notification)
Fixed inUpdated firmware from Hikvision

What you need to know

The web server bundled with a wide range of Hikvision products doesn't sufficiently validate input, so an unauthenticated attacker can send a specially crafted message that injects operating-system commands. The result is full remote code execution on the device — no login required.

Why it's about as bad as external exposure gets:

  • It's pre-authentication and network-reachable. Cameras and recorders are routinely exposed for remote access.
  • It yields full device control. Command execution on the device means the attacker owns the camera and a launch point onto the network.
  • It's been widely exploited. Security reporting documented mass exploitation, CISA lists it in KEV, and EPSS puts probability near-certain.

How serious we see it

High — the 9.8 is not hyperbole here.

Unauthenticated, network-reachable command execution on internet-facing devices, widely exploited and KEV-listed, is top-of-queue. The bounded, reassuring part is that fixed firmware exists and exposure is quick to determine. The practical catch, as with all camera bugs, is inventory: these devices are easy to lose track of, which is why they remain a favorite target years after a patch shipped.

Recommendations

Straight from Hikvision's security notification and CISA:

  1. Update firmware now. Apply the fixed firmware for your affected products.
  2. Get devices off the public internet. Put them behind a VPN or restrict access to trusted networks.
  3. Hunt and rebuild if needed. Look for signs of compromise; where a device was exposed and unpatched, reset it to known-good firmware and rotate credentials.
  4. Replace end-of-life devices. Retire models with no available fix.
  5. Confirm your exposure first. Verify whether any affected Hikvision device is reachable from the internet.

How BreachRisk sees it

BreachRisk discovers internet-facing Hikvision devices in your external footprint, fingerprints the product, and flags exposure tied to this KEV-listed CVE — surfaced at the top of your results because it's actively and widely exploited. Cameras and recorders are the classic forgotten asset; an outside-in view is how they get found before an attacker finds them.

That continuous, attacker's-eye view turns an unmanaged device on the internet into a specific, prioritized finding.

References

See your cyber risk, proven.