What is CVE-2021-36260?
This vulnerability, targeting Hikvision IP cameras, is exploited for remote code execution via CVE-2021-36260. An operator used a custom tool called 'camview' to compromise internet-exposed cameras in Ukraine. Affected devices must be urgently updated to the latest firmware and not left exposed online.
Azərbaycanca: Bu zəiflik Hikvision IP kameralarını hədəf alan və uzaqdan kod icrasına imkan verən CVE-2021-36260 boşluğundan istifadə edir. Təcavüzkar 'camview' adlı xüsusi alətlə Ukraynadakı kameraları ələ keçirib. Cihazlar dərhal ən son firmware ilə yenilənməli və internetə açıq qoyulmamalıdır.
Related CVEs
link basis: shared threat actor: Russian-speaking operator; shared vendors: D-Link, Dahua, Hikvision
FAQ2
Which manufacturer's devices does CVE-2021-36260 target?
It targets Hikvision IP cameras.
What custom tool did the attacker use when exploiting CVE-2021-36260?
A custom tool called 'camview' was used.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.