Description
Some Wi-Fi series camera products have insufficient permission validation on certain interfaces, allowing authenticated low-privileged users to obtain device Wi-Fi configuration information through these interfaces.
Published: 2026-09-10
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The vulnerability in Hikvision Wi‑Fi series cameras originates from insufficient permission validation on certain configuration interfaces. The flaw allows an authenticated user with low privileges to query the device and retrieve its Wi‑Fi configuration data, including SSIDs and passwords. This is an improper access control weakness that can lead to information disclosure. An attacker who can log into the camera could therefore expose sensitive networking credentials, facilitating further network compromise. The exposed configuration details suggest that an attacker can recover SSIDs and passwords—an inference drawn from the description that the interface returns Wi‑Fi configuration.

Affected Systems

The CVE affects Hikvision Wi‑Fi series cameras. No specific firmware version is enumerated in the advisory, but the linked release notes reference firmware version V5.7.26. Users should review the documentation for affected models and firmware builds.

Risk and Exploitability

The CVSS score of 4.3 indicates low severity; the impact is limited to disclosure to authenticated users. EPSS data is not available and the flaw is not currently listed no known widespread exploitation. An attacker must first obtain valid credentials—through credential theft, social engineering, or other means—before they can query the exposed interfaces. Once authenticated, the flaw is trivial to exploit, requiring only a simple request to the unprotected endpoints.

Generated by OpenCVE AI on September 10, 2026 at 23:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest firmware patch released by Hikvision for the Wi‑Fi series cameras, as documented in the linked release notes.
  • Enforce strict role‑based access controls on the camera’s management interfaces to prevent low‑privileged users from executing configuration queries.
  • Segregate the camera’s network or implement firewall rules to restrict external access to its management interfaces, thereby limiting the attack surface.

Generated by OpenCVE AI on September 10, 2026 at 23:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Hikvision
Hikvision wi-fi Series Camera
Vendors & Products Hikvision
Hikvision wi-fi Series Camera

Fri, 11 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Title Insufficient Permission Validation Exposes Wi‑Fi Configuration in Hikvision Cameras

Thu, 10 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Title Insufficient Permission Validation Exposes Wi‑Fi Configuration in Hikvision Cameras

Thu, 10 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Title Insufficient Permission Validation Exposes Wi‑Fi Configuration in Hikvision Cameras

Thu, 10 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Title Insufficient Permission Validation Allows Low‑Privileged Users to Retrieve Wi‑Fi Configuration from Hikvision Cameras
Weaknesses CWE-284

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Title Insufficient Permission Validation Allows Low‑Privileged Users to Retrieve Wi‑Fi Configuration from Hikvision Cameras
Weaknesses CWE-284

Thu, 10 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description Some Wi-Fi series camera products have insufficient permission validation on certain interfaces, allowing authenticated low-privileged users to obtain device Wi-Fi configuration information through these interfaces.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Hikvision Wi-fi Series Camera
cve-icon MITRE

Status: PUBLISHED

Assigner: hikvision

Published:

Updated: 2026-09-10T14:40:09.499Z

Reserved: 2026-09-04T09:24:07.712Z

Link: CVE-2026-85543

cve-icon Vulnrichment

Updated: 2026-09-10T14:39:43.142Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T13:20:32.320

Modified: 2026-09-10T15:17:49.423

Link: CVE-2026-85543

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:00:53Z

Weaknesses