OS Command Injection in Hikvision products - CVE-2021-36260
Published: February 25, 2022 / Updated: July 19, 2023
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation. A remote unauthenticated attacker can pass specially crafted data to the application and execute arbitrary OS commands on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
DS-76xxNI-K1xx(C)
DS-2TD81xx-xx/V2
DS-2TD62xx-xx/V2
DS-2TD4xxx-xx/V2
DS-2TD81xx-xx/Wx
DS-2TD62xx-xx/Wx
DS-2TD41xx-xx/Wx
DS-2TD2xxx-xx
DS-2TD1xxx-xx
DS-2TDxxxxB
DS-76xxNI-Qxx(C)
DS-2TBxxx
iDS-2VSxxxx
iDS-2SR8xxxx
iDS-2SK8xxxx
iDS-2SK7xxxx
iDS-2PT9xxxx
DS-2DF9xxxx
DS-2DF8xxxx
DS-2DF7xxxx
DS-2DF6xxxx-Cx
DS-2CD2xx1G0
(i)DS-2DExxxx
DS-2XM6xx2G0
DS-2XM6xx2FWD
DS-2XE6xx2F
DS-2XE6xx5G0
DS-2CD4xx5G0
DS-2CD4xx6FWD (Non-ANPR)
DS-2CD2x27G3E
DS-2CD2x27G1
DS-2CD2xx1G1
DS-2DF6xxxx
DS-2CD1x23G0
DS-HiWatchI-HWN-21xxHxx(C)
DS-HiWatchI-HWN-21xxMHxx(C)
DS-HiLookI-NVR-1xxHxx-D(C)
DS-HiLookI-NVR-1xxMHxx-D(C)
DS-71xxNI-Q1xx(C)
DS-HiWatchI-HWN-42xxMHxx(C)
DS-HiWatchI-HWN-41xxMHxx(C)
DS-HiLookI-NVR-2xxMHxx-C(C)
DS-HiLookI-NVR-1xxMHxx-C(C)
DS-2CD1xx7G0
DS-2CD3xx7G2
DS-2CD3xx6G2(C)
DS-2CD3xx6G2
DS-2CD2xx3G2
DS-2CD2x21G1(C)
DS-2CD2x21G0(C)
DS-2CD2xx7G2(C)
DS-2CD2xx7G2
DS-2CD2xx6G2(C)
DS-2CD2xx6G2
DS-2CD3xx7G2(C)
DS-2CD1x53(C)
DS-2CD1x53(B)
DS-2CD1x43G0E
DS-2CD1x43(C)
DS-2CD1x43(B)
DS-2CD1x23G0E(C)
DS-2CD1xx1
IPC-xxxx
HWI-xxxx
DS-2CVxxx6
DS-2XE62x2F(D)
DS-2DF5xxxx
HWP-Nxxxx
PTZ-Nxxxx
DS-2DY9xxxx
DS-2DYHxxxx
(i)DS-2SE7xxxx
(i)DS-2PTxxxx
DS-2CD8Cx6G0
DS-2XE64x2F(B)
DS-2XC66x5G0
DS-2CVxxx1
iDS-2CD6810
iDS-2XM6810
DS-2CD4xx6
DS-2CD4xx0
DS-2CD3xx3G2
DS-2CD3x51G0(C)
DS-2CD3x21G0(C)
DS-2CD3x21G0
DS-2CD3xx7G0E
How to mitigate CVE-2021-36260
Links to Public Exploits and PoC-codes
- Exploit #9193 - hikvision_brute (Brute Hikvision CAMS with CVE-2021-36260 Exploit) (July 19, 2023)
- Exploit #8208 - CVE-2021-36260 (海康威视RCE漏洞 批量检测和利用工具) (August 3, 2022)
- Exploit #8141 - CheckHKRCE (CVE-2021-36260) (July 14, 2022)
- Exploit #7832 - CVE-2021-36260-metasploit (the metasploit script(POC) about CVE-2021-36260 ) (May 16, 2022)
- Exploit #7785 - Hikvision IP Camera Unauthenticated Command Injection (May 12, 2022)
- Exploit #7526 - CVE-2021-36260 (CVE-2021-36260) (March 20, 2022)
- Exploit #7401 - Hikvision IP Camera Unauthenticated Command Injection (March 1, 2022)
- Exploit #7393 - Hikvision Web Server Build 210702 - Command Injection (February 25, 2022)
- Exploit #7392 - CVE-2021-36260 (command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability to launch a command injection attack by sending some messages with malicious comm (February 25, 2022)