Description
There is a privilege escalation vulnerability in some Hikvision cameras. Due to incorrect permission allocation in the device program, attackers can escalate privileges and gain full control of the device after authenticating via SSH.
Published: 2026-07-22
Score: 6.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

HiKVision cameras in the DS-2CD series contain an incorrect permission allocation bug that allows an attacker who has authenticated through SSH to elevate privileges. Once authenticated, the attacker can gain full control of the device, including ability to execute arbitrary commands, alter configuration, and potentially access recorded footage. The flaw stems from improper privilege management and is a classic example of CWE-269 vulnerability.

Affected Systems

The affected products are Hikvision DS-2CD series cameras. No specific firmware or version range is supplied in the advisory, so any camera running the affected firmware may be susceptible. Users should verify their camera model and firmware version against the advisory’s supported list and review recent updates from Hikvision.

Risk and Exploitability

The CVSS score of 6.6 classifies the vulnerability as medium severity. The EPSS score is below 1%, suggesting the likelihood of exploitation is low at the present time. Because it is not listed in the CISA KEV catalog, there are no widespread reported exploits. Attackers need to authenticate via SSH, which means either compromised credentials or a device with weak or default keys are. Once authenticated, privilege escalation is straightforward, giving an attacker complete control over the camera.

Generated by OpenCVE AI on August 4, 2026 at 00:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the camera firmware to the latest Hikvision release that addresses the permission allocation issue.
  • Restrict SSH access by disabling unused accounts or limiting login to a secure network segment.
  • Continuously monitor for unexpected administrative activity on the cameras and enforce strong, unique passwords for SSH access.

Generated by OpenCVE AI on August 4, 2026 at 00:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Incorrect Permission Allocation in Hikvision DS-2CD Series Cameras

Sun, 02 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via SSH in Hikvision DS-2CD Cameras

Thu, 30 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via SSH in Hikvision DS-2CD Cameras

Tue, 28 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Incorrect Permission Allocation on Hikvision Cameras

Mon, 27 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Hikvision
Hikvision ds-2cd Series
Vendors & Products Hikvision
Hikvision ds-2cd Series

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Incorrect Permission Allocation on Hikvision Cameras

Wed, 22 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description There is a privilege escalation vulnerability in some Hikvision cameras. Due to incorrect permission allocation in the device program, attackers can escalate privileges and gain full control of the device after authenticating via SSH.
References
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Hikvision Ds-2cd Series
cve-icon MITRE

Status: PUBLISHED

Assigner: hikvision

Published:

Updated: 2026-07-22T12:44:49.458Z

Reserved: 2026-06-25T02:07:05.126Z

Link: CVE-2026-57599

cve-icon Vulnrichment

Updated: 2026-07-22T12:44:36.512Z

cve-icon NVD

Status : Deferred

Published: 2026-07-22T12:18:16.757

Modified: 2026-07-22T20:50:36.493

Link: CVE-2026-57599

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T00:15:04Z

Weaknesses
  • CWE-269

    Improper Privilege Management