Skip to content
COOEY

EXPOSURES › CVE-2021-36260

CVE-2021-36260

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-01-10 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-36260 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatched

Hikvision security cameras suffered from an unpatched command injection flaw actively exploited in the wild.

Hikvision's web server in its security cameras had insufficient input validation, allowing attackers to inject and execute arbitrary commands. This unpatched vulnerability was actively exploited in the wild, posing a severe risk to organizations relying on these cameras for physical security and surveillance. DIB organizations must ensure all IoT and OT devices are patched and monitored for known KEV vulnerabilities to prevent similar compromises.

Shame score — The vendor shipped products with a known, unpatched command injection vulnerability that was actively exploited in the wild, demonstrating a severe lack of security hygiene and negligence.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.