Description
There is a information disclosure vulnerability in some Hikvision cameras, allowing unauthenticated attackers to obtain partial information from the device’s memory.
Published: 2026-07-22
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows unauthenticated attackers to read portions of the camera’s memory, potentially exposing sensitive configuration or identification details. This is a classic information disclosure weakness (CWE‑200) that can compromise the confidentiality of the device.

Affected Systems

Affected devices include Hikvision DS-2CD and DS-2DE series cameras. No specific firmware or model version information is provided, so any camera in those series may be vulnerable until confirmation.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity, while the EPSS score of less than 1% suggests a very low likelihood of exploitation in the wild. Because the vulnerability is unauthenticated, the likely attack vector is remote, network‑based access to the camera’s exposed interfaces, but no exploit has been reported or listed in CISA’s KEV catalog.

Generated by OpenCVE AI on August 4, 2026 at 00:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check for and install the latest firmware or patch released by Hikvision for the affected camera models.
  • Restrict external network access to the cameras by placing them behind a firewall or VLAN and disabling unnecessary remote services.
  • If available, disable or limit memory‑read functionalities or remote management options via the camera’s configuration settings.

Generated by OpenCVE AI on August 4, 2026 at 00:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Information Disclosure in Hikvision DS-2CD/DS-2DE Series Cameras

Thu, 30 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Information Disclosure in Hikvision DS-2CD/DS-2DE Series Cameras

Tue, 28 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Information Disclosure in Hikvision DS‑2CD and DS‑2DE Camera Series

Mon, 27 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Hikvision
Hikvision ds-2cd Series
Hikvision ds-2de Series
Vendors & Products Hikvision
Hikvision ds-2cd Series
Hikvision ds-2de Series

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Information Disclosure in Hikvision DS‑2CD and DS‑2DE Camera Series

Wed, 22 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description There is a information disclosure vulnerability in some Hikvision cameras, allowing unauthenticated attackers to obtain partial information from the device’s memory.
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Hikvision Ds-2cd Series Ds-2de Series
cve-icon MITRE

Status: PUBLISHED

Assigner: hikvision

Published:

Updated: 2026-07-22T12:29:21.886Z

Reserved: 2026-07-09T05:51:16.531Z

Link: CVE-2026-61392

cve-icon Vulnrichment

Updated: 2026-07-22T12:29:18.656Z

cve-icon NVD

Status : Deferred

Published: 2026-07-22T12:18:18.350

Modified: 2026-07-22T20:50:36.493

Link: CVE-2026-61392

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T00:15:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor