{"id":28738,"date":"2022-07-02T05:11:07","date_gmt":"2022-07-02T10:11:07","guid":{"rendered":"https:\/\/learncctv.com\/?p=28738"},"modified":"2022-07-18T15:42:20","modified_gmt":"2022-07-18T20:42:20","slug":"hikvision-critical-vulnerability","status":"publish","type":"post","link":"https:\/\/learncctv.com\/hikvision-critical-vulnerability\/","title":{"rendered":"Hikvision Critical Vulnerability [ Important ]"},"content":{"rendered":"\n<p>Hikvision administrators have claimed there is &#8220;a zero-click vulnerability&#8221; in the majority of their security cameras. In this article, you&#8217;ll learn about Hikvision Critical Vulnerability.<\/p>\n\n\n\n<p>Additionally, there is a possibility that an unauthenticated hacker can gain access to your NVR and even internal networks. Details of said Remote Code Execution (RCE) bug in certain Hikvision products that can bypass usernames and passwords have been leaked.<\/p>\n\n\n\n<p>This exposure can be exploited to the point of gaining access to a device and being able to control it. A hacker can also use said compromised devices to gain further access to internal networks.<\/p>\n\n\n\n<p>Overall, more than 70 <a href=\"https:\/\/amzn.to\/3yn8eK2\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Hikvision cameras<\/a> and NVRs are exposed to this critical vulnerability. And more than 100 million devices were affected by the issue. Want to find out more about the topic? Check out: <a href=\"https:\/\/learncctv.com\/are-hikvision-cameras-secure\/\" target=\"_blank\" rel=\"noreferrer noopener\">Are Hikvision cameras secure?<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How does the Hikvision Critical Vulnerability work?<\/h2>\n\n\n\n<p>Usually, access to the&nbsp;<em>HTTPS&nbsp;<\/em>server port is the only thing needed. Typically the&nbsp;<em>80\/443&nbsp;<\/em>server port is used to target<em>&nbsp;<\/em>Hikvision Critical Vulnerability.<\/p>\n\n\n\n<p>Passwords and usernames are not necessary for an attacker to target the camera. Plus, they do not rely on the user for any action. And cannot be detected once they log into the camera.&nbsp;<\/p>\n\n\n\n<p>This vulnerability to bugs has been present in the firmware since 2016 and has been both acknowledged and repaired by Hikvision. The brand also released a security advisory to alert users of at-risk products.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Why Hikvision Critical Vulnerability happens<\/h3>\n\n\n\n<p>Because there is insufficient input validation, an attacker can take advantage of this flaw by submitting messages that include malicious commands to initiate a command attack.&nbsp;<\/p>\n\n\n\n<p>According to Watchful-IP, this flaw enables complete control of the embedded computer and unlimited root access.&nbsp;<\/p>\n\n\n\n<p>The device owner is only allowed to use a limited &#8220;protected shell&#8221; (psh), which restricts input to a pre-determined list of limited, vastly informative commands. Yet the attacker can acquire complete control of the device with an unlimited root shell.<\/p>\n\n\n\n<p>This means that internal networks may also be &#8220;accessed and attacked&#8221; using the vulnerability.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Does this vulnerability affect OEM versions?&nbsp;<\/h3>\n\n\n\n<p>Yes, there will be effects on the OEM versions. Actually, this flaw affects practically all OEM and Hikvision-branded cameras.&nbsp;<\/p>\n\n\n\n<p>Additionally, hundreds of brands throughout the world will be impacted by the vulnerability since <a href=\"https:\/\/amzn.to\/3yn8eK2\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Hikvision cameras<\/a> are so widely used.&nbsp;<\/p>\n\n\n\n<p>Moreover, the worst thing is that many OEM brands for Hikvision attempt to conceal their affiliation with Hikvision and pass the cameras off as their own, which means they&#8217;ll ignore this vulnerability, and many consumers won&#8217;t even be aware of it.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Versions Impacted<\/h2>\n\n\n\n<p>Below is a list of some of the impacted versions. If you own a camera model listed, its&nbsp;<strong>firmware must be updated IMMEDIATELY<\/strong>.<\/p>\n\n\n\n<figure class=\"wp-block-table is-style-stripes\"><table><tbody><tr><td><strong>Product name<\/strong><\/td><td><strong>Affected version(s)<\/strong><\/td><\/tr><tr><td>DS-2CD1x23<br>DS-2CD1x43(B)<br>DS-2CD1x43(C)<br>DS-2CD1x43G0E<br>DS-2CD1x53(B)<br>DS-2CD1x53(C)<br>DS-2CD1xx1<br>DS-2CD1xx7G0<br>DS-2CD2x21G0<br>DS-2CD2xx3G2<br>DS-2CD2xx6G2<br>DS-2CD2xx7G2<br>DS-2CD3x21G0<br>DS-2CD3x51G0<br>DS-2CD3xx3G2<br>DS-2CD3xx6G2<br>DS-2CD3xx7G0E<br>DS-2CD3xx7G2<br>DS-2CD4xx0<br>DS-2CD4xx6<br>DS-2CD5xx5<br>DS-2CD5xx7<br>DS-2CD7xx6G0<br>DS-2CD8Cx6G0<br>DS-2CVxxx1<br>DS-2CVxxx5<br>DS-2CVxxx6<br>DS-2DF5xxxx<br>DS-2DF6xxxx<br>DS-2DF6xxxx-Cx<br>DS-2DF7xxxx<br>DS-2DF8xxxx<br>DS-2DF9xxxx<br>DS-2DYHxxxx<br>DS-2XC66x5G0<br>DS-2XE30x6FWD(B)<br>DS-2XE60x6FWD(B)<br>DS-2XE62x2F(D)<br>DS-2XE62x7FWD(D)<br>DS-2XE64x2F(B)<br>DS-DY9xxxx<br>HWI-xxxx<br>HWP-Nxxxx<br>IPC-xxxx<br>KBA18(C)-83x6FWD<br>PTZ-Nxxxx<br>iDS-2CD6810<br>iDS-2DExxxx<br>iDS-2PT9xxxx<br>iDS-2PTxxxx<br>iDS-2SE7xxxx<br>iDS-2SK7xxxx<br>iDS-2SK8xxxx<br>iDS-2SR8xxxx<br>iDS-2VSxxxx<br>iDS-2XM6810<\/td><td>Versions which Build time before 210625<\/td><\/tr><tr><td>DS-2TBxxx<br>DS-2TD1xxx-xx<br>DS-2TD2xxx-xx<br>DS-2TD41xx-xx\/Wx<br>DS-2TD4xxx-xx\/V2<br>DS-2TD62xx-xx\/V2<br>DS-2TD62xx-xx\/Wx<br>DS-2TD81xx-xx\/V2<br>DS-2TD81xx-xx\/Wx<br>DS-2TDxxxxB<br>DS-Bxxxx<\/td><td>Versions which Build time before 210702<\/td><\/tr><tr><td>DS-76xxNI-K1xx(C)<br>DS-76xxNI-Qxx(C)<br>DS-HiLookI-NVR-1xxMHxx(C)<br>DS-HiLookI-NVR-2xxMHxx(C)<br>DS-HiWatchI-HWN-41xxMHxx(C)<br>DS-HiWatchI-HWN-42xxMHxx(C)<\/td><td>V4.30.210 Build201224 \u2013 V4.31.000 Build210511<\/td><\/tr><tr><td>DS-71xxNI-Q1xx(C)<br>DS-HiLookI-NVR-1xxHxx(C)<br>DS-HiLookI-NVR-1xxMHxx(C)<br>DS-HiWatchI-HWN-21xxHxx(C)<br>DS-HiWatchI-HWN-21xxMHxx(C)<\/td><td>V4.30.300 Build210221 \u2013 V4.31.100 Build210511<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Final Thoughts<\/h2>\n\n\n\n<p>Though Hikvision Critical Vulnerability can be a downside to its products, it does not reflect on the company as a whole as its lineup of products is worth investing in.<\/p>\n\n\n\n<p>Furthermore, it would be best if you always protected yourself and placed cameras in areas that do not expose your privacy on the occasion that someone can access the footage. Never place any cameras in bedrooms, bathrooms, or other private spaces.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hikvision administrators have claimed there is &#8220;a zero-click vulnerability&#8221; in the majority of their security cameras. In this article, you&#8217;ll learn about Hikvision Critical Vulnerability. Additionally, there is a possibility that an unauthenticated hacker can gain access to your NVR and even internal networks. Details of said Remote Code Execution (RCE) bug in certain Hikvision [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":23488,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[118,212],"tags":[],"class_list":["post-28738","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cctv","category-hikvision"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.2 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Hikvision Critical Vulnerability [ Important ] - Learn CCTV.com<\/title>\n<meta name=\"description\" content=\"In this article, you&#039;ll learn about Hikvision Critical Vulnerability and why it is incredibly dangerous to you and your devices.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/learncctv.com\/hikvision-critical-vulnerability\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Hikvision Critical Vulnerability [ Important ] - Learn CCTV.com\" \/>\n<meta property=\"og:description\" content=\"In this article, you&#039;ll learn about Hikvision Critical Vulnerability and why it is incredibly dangerous to you and your devices.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/learncctv.com\/hikvision-critical-vulnerability\/\" \/>\n<meta property=\"og:site_name\" content=\"Learn CCTV.com\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/learncctvnow\" \/>\n<meta property=\"article:published_time\" content=\"2022-07-02T10:11:07+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-07-18T20:42:20+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/learncctv.com\/wp-content\/uploads\/2021\/03\/Hikvision-Cube-Wireless-camera1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"450\" \/>\n\t<meta property=\"og:image:height\" content=\"614\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Amanda Martins\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Amanda Martins\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/learncctv.com\/hikvision-critical-vulnerability\/\",\"url\":\"https:\/\/learncctv.com\/hikvision-critical-vulnerability\/\",\"name\":\"Hikvision Critical Vulnerability [ Important ] - Learn CCTV.com\",\"isPartOf\":{\"@id\":\"https:\/\/learncctv.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/learncctv.com\/hikvision-critical-vulnerability\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/learncctv.com\/hikvision-critical-vulnerability\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/learncctv.com\/wp-content\/uploads\/2021\/03\/Hikvision-Cube-Wireless-camera1.jpg\",\"datePublished\":\"2022-07-02T10:11:07+00:00\",\"dateModified\":\"2022-07-18T20:42:20+00:00\",\"author\":{\"@id\":\"https:\/\/learncctv.com\/#\/schema\/person\/e8f65b25da2fd6dc8d91b835e2f22c25\"},\"description\":\"In this article, you'll learn about Hikvision Critical Vulnerability and why it is incredibly dangerous to you and your devices.\",\"breadcrumb\":{\"@id\":\"https:\/\/learncctv.com\/hikvision-critical-vulnerability\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/learncctv.com\/hikvision-critical-vulnerability\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/learncctv.com\/hikvision-critical-vulnerability\/#primaryimage\",\"url\":\"https:\/\/learncctv.com\/wp-content\/uploads\/2021\/03\/Hikvision-Cube-Wireless-camera1.jpg\",\"contentUrl\":\"https:\/\/learncctv.com\/wp-content\/uploads\/2021\/03\/Hikvision-Cube-Wireless-camera1.jpg\",\"width\":450,\"height\":614,\"caption\":\"Hikvision Cube Wireless camera\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/learncctv.com\/hikvision-critical-vulnerability\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/learncctv.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Hikvision Critical Vulnerability [ Important ]\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/learncctv.com\/#website\",\"url\":\"https:\/\/learncctv.com\/\",\"name\":\"Learn CCTV.com\",\"description\":\"The place where you can learn CCTV\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/learncctv.com\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/learncctv.com\/#\/schema\/person\/e8f65b25da2fd6dc8d91b835e2f22c25\",\"name\":\"Amanda Martins\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/learncctv.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/6ab65fed62f43e85fb55dfaf83803523?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/6ab65fed62f43e85fb55dfaf83803523?s=96&d=mm&r=g\",\"caption\":\"Amanda Martins\"},\"url\":\"https:\/\/learncctv.com\/author\/amandamartinsusagmail-com\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Hikvision Critical Vulnerability [ Important ] - Learn CCTV.com","description":"In this article, you'll learn about Hikvision Critical Vulnerability and why it is incredibly dangerous to you and your devices.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/learncctv.com\/hikvision-critical-vulnerability\/","og_locale":"en_US","og_type":"article","og_title":"Hikvision Critical Vulnerability [ Important ] - Learn CCTV.com","og_description":"In this article, you'll learn about Hikvision Critical Vulnerability and why it is incredibly dangerous to you and your devices.","og_url":"https:\/\/learncctv.com\/hikvision-critical-vulnerability\/","og_site_name":"Learn CCTV.com","article_publisher":"https:\/\/www.facebook.com\/learncctvnow","article_published_time":"2022-07-02T10:11:07+00:00","article_modified_time":"2022-07-18T20:42:20+00:00","og_image":[{"width":450,"height":614,"url":"https:\/\/learncctv.com\/wp-content\/uploads\/2021\/03\/Hikvision-Cube-Wireless-camera1.jpg","type":"image\/jpeg"}],"author":"Amanda Martins","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Amanda Martins","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/learncctv.com\/hikvision-critical-vulnerability\/","url":"https:\/\/learncctv.com\/hikvision-critical-vulnerability\/","name":"Hikvision Critical Vulnerability [ Important ] - Learn CCTV.com","isPartOf":{"@id":"https:\/\/learncctv.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/learncctv.com\/hikvision-critical-vulnerability\/#primaryimage"},"image":{"@id":"https:\/\/learncctv.com\/hikvision-critical-vulnerability\/#primaryimage"},"thumbnailUrl":"https:\/\/learncctv.com\/wp-content\/uploads\/2021\/03\/Hikvision-Cube-Wireless-camera1.jpg","datePublished":"2022-07-02T10:11:07+00:00","dateModified":"2022-07-18T20:42:20+00:00","author":{"@id":"https:\/\/learncctv.com\/#\/schema\/person\/e8f65b25da2fd6dc8d91b835e2f22c25"},"description":"In this article, you'll learn about Hikvision Critical Vulnerability and why it is incredibly dangerous to you and your devices.","breadcrumb":{"@id":"https:\/\/learncctv.com\/hikvision-critical-vulnerability\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/learncctv.com\/hikvision-critical-vulnerability\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/learncctv.com\/hikvision-critical-vulnerability\/#primaryimage","url":"https:\/\/learncctv.com\/wp-content\/uploads\/2021\/03\/Hikvision-Cube-Wireless-camera1.jpg","contentUrl":"https:\/\/learncctv.com\/wp-content\/uploads\/2021\/03\/Hikvision-Cube-Wireless-camera1.jpg","width":450,"height":614,"caption":"Hikvision Cube Wireless camera"},{"@type":"BreadcrumbList","@id":"https:\/\/learncctv.com\/hikvision-critical-vulnerability\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/learncctv.com\/"},{"@type":"ListItem","position":2,"name":"Hikvision Critical Vulnerability [ Important ]"}]},{"@type":"WebSite","@id":"https:\/\/learncctv.com\/#website","url":"https:\/\/learncctv.com\/","name":"Learn CCTV.com","description":"The place where you can learn CCTV","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/learncctv.com\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/learncctv.com\/#\/schema\/person\/e8f65b25da2fd6dc8d91b835e2f22c25","name":"Amanda Martins","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/learncctv.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/6ab65fed62f43e85fb55dfaf83803523?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/6ab65fed62f43e85fb55dfaf83803523?s=96&d=mm&r=g","caption":"Amanda Martins"},"url":"https:\/\/learncctv.com\/author\/amandamartinsusagmail-com\/"}]}},"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/learncctv.com\/wp-json\/wp\/v2\/posts\/28738"}],"collection":[{"href":"https:\/\/learncctv.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/learncctv.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/learncctv.com\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/learncctv.com\/wp-json\/wp\/v2\/comments?post=28738"}],"version-history":[{"count":4,"href":"https:\/\/learncctv.com\/wp-json\/wp\/v2\/posts\/28738\/revisions"}],"predecessor-version":[{"id":28800,"href":"https:\/\/learncctv.com\/wp-json\/wp\/v2\/posts\/28738\/revisions\/28800"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/learncctv.com\/wp-json\/wp\/v2\/media\/23488"}],"wp:attachment":[{"href":"https:\/\/learncctv.com\/wp-json\/wp\/v2\/media?parent=28738"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/learncctv.com\/wp-json\/wp\/v2\/categories?post=28738"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/learncctv.com\/wp-json\/wp\/v2\/tags?post=28738"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}