CVE-2021-36260: Hikvision unauthenticated command injection, actively exploited
The short version: Many Hikvision products have a command-injection flaw in their web server (CVE-2021-36260) that lets an unauthenticated attacker run arbitrary commands on the device by sending a crafted message. It's in CISA's KEV catalog, it's been widely exploited, and EPSS puts exploitation near-certain. Update firmware and get these devices off the open internet. Steady hands — but move.
At a glance
| Fact | Detail |
|---|---|
| Our severity take | High — unauthenticated RCE, widely exploited |
| CVSS v3.1 (NVD) | 9.8 — Critical · AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVSS v2 (NVD) | 9.3 — High |
| EPSS | ~99.87% · 99th percentile (2026-07-17) |
| In CISA KEV? | Yes — remediate by 2022-01-24 |
| Known exploited? | Yes — widespread exploitation reported; listed in CISA KEV |
| Vulnerability type | CWE-78 OS command injection → unauthenticated remote code execution |
| Requires authenticated session? | No — pre-authentication |
| Affected | Numerous Hikvision products with the affected web-server firmware (see the vendor security notification) |
| Fixed in | Updated firmware from Hikvision |
What you need to know
The web server bundled with a wide range of Hikvision products doesn't sufficiently validate input, so an unauthenticated attacker can send a specially crafted message that injects operating-system commands. The result is full remote code execution on the device — no login required.
Why it's about as bad as external exposure gets:
- It's pre-authentication and network-reachable. Cameras and recorders are routinely exposed for remote access.
- It yields full device control. Command execution on the device means the attacker owns the camera and a launch point onto the network.
- It's been widely exploited. Security reporting documented mass exploitation, CISA lists it in KEV, and EPSS puts probability near-certain.
How serious we see it
High — the 9.8 is not hyperbole here.
Unauthenticated, network-reachable command execution on internet-facing devices, widely exploited and KEV-listed, is top-of-queue. The bounded, reassuring part is that fixed firmware exists and exposure is quick to determine. The practical catch, as with all camera bugs, is inventory: these devices are easy to lose track of, which is why they remain a favorite target years after a patch shipped.
Recommendations
Straight from Hikvision's security notification and CISA:
- Update firmware now. Apply the fixed firmware for your affected products.
- Get devices off the public internet. Put them behind a VPN or restrict access to trusted networks.
- Hunt and rebuild if needed. Look for signs of compromise; where a device was exposed and unpatched, reset it to known-good firmware and rotate credentials.
- Replace end-of-life devices. Retire models with no available fix.
- Confirm your exposure first. Verify whether any affected Hikvision device is reachable from the internet.
How BreachRisk sees it
BreachRisk discovers internet-facing Hikvision devices in your external footprint, fingerprints the product, and flags exposure tied to this KEV-listed CVE — surfaced at the top of your results because it's actively and widely exploited. Cameras and recorders are the classic forgotten asset; an outside-in view is how they get found before an attacker finds them.
That continuous, attacker's-eye view turns an unmanaged device on the internet into a specific, prioritized finding.