CVE-2021-36260
CRITICALA command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability to launch a command injection…
EPSS Exploitation Probability
EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.
Description
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability to launch a command injection attack by sending some messages with malicious commands.
Affected Products
ds-2cd2021g1-i\(w\) firmwarehikvisionds-2cd2023g2-i\(u\) firmwarehikvisionds-2cd2026g2-iu\/sl firmwarehikvisionds-2cd2027g2-l\(u\) firmwarehikvisionds-2cd2027g2-lu\/sl firmwarehikvisionds-2cd2043g2-i\(u\) firmwarehikvisionResearch use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.
Hikvision Web Server Build 210702 - Command Injection
by bashis · Oct 25, 2021
Frequently Asked Questions
Is CVE-2021-36260 in your stack?
O3 detects CVE-2021-36260 across dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.