Description
Some Hikvision Networking Products are vulnerable to authenticated command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution.
Published: 2026-07-31
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw stems from insufficient input validation in certain Hikvision Networking Products. An attacker who possesses valid credentials can craft specially formatted packets that carry arbitrary system or shell commands. When these packets are processed, the device executes the contained commands with the privileges of the authenticated session, enabling full command execution on the device. This is a classic command injection vulnerability, classified as CWE‑78.

Affected Systems

The vulnerability affects Hikvision DS‑3WAP521‑SI, DS‑3WAP522‑SI, DS‑3WAP621E‑SI, DS‑3WAP622E‑SI, DS‑3WAP622G‑SI, DS‑3WAP623E‑SI, DS‑3WG105G‑SI, DS‑3WG105GP‑SI, DS‑3WG210GP‑SI, and DS‑3WG507G‑SI wireless access points. No specific firmware or serial number ranges are provided in the advisory.

Risk and Exploitability

The CVSS score of 7.2 indicates high severity. With an EPSS score under 1 % and not being listed in the CISA KEV catalog, large‑scale exploitation has not yet been documented. The flaw requires valid credentials, so the attack vector is an authenticated remote attack, typically limited to insiders or compromised users. The risk remains moderate; while widespread exploitation probability is low, the potential impact of successful exploitation is severe enough to warrant immediate attention.

Generated by OpenCVE AI on August 4, 2026 at 11:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update for the affected Hikvision wireless access points that addresses the input validation issue.
  • Restrict access to device configuration interfaces and enforce least‑privilege credentials to reduce the potential for authenticated exploitation.
  • Enable and regularly review device logging to detect suspicious command execution attempts, and configure network segmentation to limit the blast radius of any compromise.

Generated by OpenCVE AI on August 4, 2026 at 11:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Title Authenticated Command Execution Vulnerability in Hikvision Wireless APs

Mon, 03 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Description Some Hikvision Wireless Access Points are vulnerable to authenticated command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution. Some Hikvision Networking Products are vulnerable to authenticated command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution.

Sun, 02 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
Title Authenticated Command Execution Vulnerability in Hikvision Wireless APs

Fri, 31 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-78
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 31 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Hikvision
Hikvision ds-3wap521-si
Hikvision ds-3wap522-si
Hikvision ds-3wap621e-si
Hikvision ds-3wap622e-si
Hikvision ds-3wap622g-si
Hikvision ds-3wap623e-si
Vendors & Products Hikvision
Hikvision ds-3wap521-si
Hikvision ds-3wap522-si
Hikvision ds-3wap621e-si
Hikvision ds-3wap622e-si
Hikvision ds-3wap622g-si
Hikvision ds-3wap623e-si

Fri, 31 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Description Some Hikvision Wireless Access Points are vulnerable to authenticated command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution.
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Hikvision Ds-3wap521-si Ds-3wap522-si Ds-3wap621e-si Ds-3wap622e-si Ds-3wap622g-si Ds-3wap623e-si
cve-icon MITRE

Status: PUBLISHED

Assigner: hikvision

Published:

Updated: 2026-08-03T05:56:30.541Z

Reserved: 2026-07-24T03:06:45.941Z

Link: CVE-2026-16843

cve-icon Vulnrichment

Updated: 2026-07-31T16:31:18.704Z

cve-icon NVD

Status : Received

Published: 2026-07-31T11:17:05.567

Modified: 2026-08-03T07:16:42.357

Link: CVE-2026-16843

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T11:30:07Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')