Impact
HiKVision cameras in the DS-2CD series contain an incorrect permission allocation bug that allows an attacker who has authenticated through SSH to elevate privileges. Once authenticated, the attacker can gain full control of the device, including ability to execute arbitrary commands, alter configuration, and potentially access recorded footage. The flaw stems from improper privilege management and is a classic example of CWE-269 vulnerability.
Affected Systems
The affected products are Hikvision DS-2CD series cameras. No specific firmware or version range is supplied in the advisory, so any camera running the affected firmware may be susceptible. Users should verify their camera model and firmware version against the advisory’s supported list and review recent updates from Hikvision.
Risk and Exploitability
The CVSS score of 6.6 classifies the vulnerability as medium severity. The EPSS score is below 1%, suggesting the likelihood of exploitation is low at the present time. Because it is not listed in the CISA KEV catalog, there are no widespread reported exploits. Attackers need to authenticate via SSH, which means either compromised credentials or a device with weak or default keys are. Once authenticated, privilege escalation is straightforward, giving an attacker complete control over the camera.
OpenCVE Enrichment