Skip to content
COOEY

FAIL › dossier

Hikvision

VENDOR

· dossier confidence 0%

Hikvision is a surveillance vendor with a documented history of high-severity, unpatched vulnerabilities in its products, including remote code execution and command injection flaws that were exploited in the wild.

PROFILE
CategoryvendorWhat they doHikvision is a vendor that provides security and surveillance products.
SECURITY POSTURE

Hikvision has a poor security posture, evidenced by multiple high-severity remote code execution (RCE) vulnerabilities in its products that remained unpatched and were actively exploited.

Notable failures
  • CVE-2017-7921 unpatched RCE
  • CVE-2021-36260 command injection
Patterns: repeated unpatched edge-device RCEs; insufficient input validation in web servers
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2022-01-10 CVE-2021-36260 high Hikvision security cameras suffered from an unpatched command injection flaw actively exploited in the wild.
2026-03-05 CVE-2017-7921 high Hikvision products had unpatched, exploited improper authentication vulns.
Open questions: What is the current patching cadence for Hikvision firmware updates? · Are there any ongoing active exploits targeting Hikvision CVE-2021-36260?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-11 03:56:13.784608+00:00