EXPOSURES › CVE-2021-36260
CVE-2021-36260
HIGH ⌖ ON CISA KEV · EXPLOITEDHikvision security cameras suffered from an unpatched command injection flaw actively exploited in the wild.
Hikvision's web server in its security cameras had insufficient input validation, allowing attackers to inject and execute arbitrary commands. This unpatched vulnerability was actively exploited in the wild, posing a severe risk to organizations relying on these cameras for physical security and surveillance. DIB organizations must ensure all IoT and OT devices are patched and monitored for known KEV vulnerabilities to prevent similar compromises.
Shame score — The vendor shipped products with a known, unpatched command injection vulnerability that was actively exploited in the wild, demonstrating a severe lack of security hygiene and negligence.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation.