Hikvision vulnerabilities
12 CVEs tracked
Hikvision consistently appears in our reporting as a vendor with a long history of vulnerabilities and a frequent target of internet-wide scans. The main theme involves exploitation by a Russian-speaking operator using a custom toolset called 'camview' to target cameras in Ukraine. Recent reports highlight several new CVEs, including unauthenticated partial data retrieval (CVE-2026-57600), a heap-based buffer overflow (CVE-2026-61390), and a post-authentication SSH privilege escalation (CVE-2026-57599). Defenders should ensure these devices are not internet-exposed, apply firmware updates, and monitor for scans targeting the Hikvision Intelligent Security API for early anomaly detection.
Azərbaycanca: Hikvision hesabatlarımızda uzun müddətdir davam edən zəifliklər tarixi və internet üzərindən genişmiqyaslı skan hədəfi kimi görünür. Əsas hadisələr xüsusilə Rusdilli operatorların Ukraynadakı kameraları hədəf alan 'camview' alət dəsti ilə bağlıdır. Son hesabatlarda autentifikasiya olunmamış məlumat sızması (CVE-2026-57600), yığın bufer daşması (heap-based buffer overflow) (CVE-2026-61390) və autentifikasiya sonrası SSH vasitəsilə imtiyaz yüksəltmə (CVE-2026-57599) daxil olmaqla bir neçə yeni CVE qeyd edilmişdir. Müdafiəçilər bu cihazların internetə açıq olmamasına xüsusi diqqət yetirməli, firmware yeniləmələrini tətbiq etməli və anomaliyaları aşkar etmək üçün Hikvision Intelligent Security API skanlarına nəzarət etməlidir.
This vendor's CVEs12
This hub is built from skopnix's own reporting on Hikvision: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.