LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-36260: Hikvision Improper Input Validation

RBRecent Breaches Vulnerability Intelligence·Jan 10, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jan 24, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-36260 to its Known Exploited Vulnerabilities catalog on Jan 10, 2022, with a federal patch deadline of Jan 24, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation.

CVE-2021-36260 is a command injection vulnerability in the web server component of some Hikvision security cameras. Insufficient input validation lets an attacker supply crafted input that the device may execute as operating-system commands. Because these cameras are often reachable from internal networks or the internet and sit on the edge of physical-security and IT environments, successful abuse can give an attacker a foothold for further lateral movement or device takeover. CISA lists the required action as applying updates per the vendor’s instructions; ransomware use is not documented for this CVE.

How it works

The underlying weakness is CWE-78 (OS Command Injection). The camera’s web server accepts parameters from HTTP requests and, because of inadequate validation or sanitization, can pass attacker-controlled data into a command interpreter. An unauthenticated or low-privilege remote attacker who can reach the web interface may therefore cause the device to run arbitrary commands with the privileges of the web-server process. Exact request formats, parameters, and preconditions are not repeated here; defenders must confirm the precise attack surface and any authentication requirements against the current Hikvision advisory for CVE-2021-36260.

Am I affected? How to find it in your systems

Hikvision cameras and related video products commonly expose an HTTP/HTTPS management interface on the local network or, if misconfigured, on the public internet. Inventory steps:

Telemetry that may indicate exploitation attempts includes unusual HTTP requests containing shell metacharacters or unexpected command-like strings directed at the camera’s web paths, sudden outbound connections from camera IP addresses, or unexplained process or configuration changes on the device. Because public detail on exact indicators is limited, treat any anomalous web traffic to these devices as suspicious and validate against the vendor advisory and your own baselines.

How to remediate

Patch first. Obtain and apply the firmware or software updates that Hikvision released for the affected products, following the vendor’s installation instructions and any prerequisite steps. After updating:

Verify the installed version matches a fixed release listed by the vendor before closing the ticket.

If you can't patch immediately

Until the vendor update can be deployed, reduce exposure with compensating controls:

These measures lower risk but do not replace the patch; schedule the official update as soon as possible.

If your data may have been exposed

Actively exploited command-injection flaws on network-connected devices can lead to full device compromise and subsequent network intrusion. If you have reason to believe cameras were reachable and unpatched during the period of exposure, treat the incident as a potential breach: isolate affected devices, preserve logs, and begin standard incident-response procedures. You can also run a free exposure scan of your email addresses against known breach data sets to see whether credentials or other information associated with your organization have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedHikvision · Security cameras web server
WeaknessCWE-78
Added to CISA KEVJan 10, 2022
Federal patch deadlineJan 24, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities