CISA Known Exploited Vulnerability

CVE-2021-36260

Hikvision · Security cameras web server

Hikvision Improper Input Validation

Date added
BOD 22-01 due date
CWE CWE-78
Ransomware Unknown

CISA description

A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation.

Required action

Apply updates per vendor instructions.