Description
Some Wi-Fi series camera products have insufficient permission validation on certain interfaces, allowing authenticated low-privileged users to obtain device Wi-Fi configuration information through these interfaces.
Published: 2026-09-10
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The vulnerability in Hikvision Wi‑Fi series cameras originates from insufficient permission validation on certain configuration interfaces. The flaw allows an authenticated user with low privileges to query the device and retrieve its Wi‑Fi configuration data, including SSIDs and passwords. This is an improper access control weakness that can lead to information disclosure. An attacker who can log into the camera could therefore expose sensitive networking credentials, facilitating further network compromise.

Affected Systems

The CVE affects Hikvision Wi‑Fi series cameras. No specific firmware version is enumerated in the advisory, but the linked release notes reference firmware version V5.7.26. Users should review the documentation for affected models and firmware builds.

Risk and Exploitability

The CVSS score of 4.3 reflects moderate severity; the impact is limited to disclosure to authenticated users. EPSS data is not available and the flaw is not currently listed in the CISA KEV catalog, indicating no known widespread exploitation. An attacker must first obtain valid credentials—through credential theft, social engineering, or other means—before they can query the exposed interfaces. Once authenticated, the flaw is trivial to exploit, requiring only a simple request to the unprotected endpoints.

Generated by OpenCVE AI on September 10, 2026 at 19:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware patch released by Hikvision for the Wi‑Fi series cameras, as documented in the linked release notes.
  • Enforce strict role‑based access controls on the camera’s management interfaces to prevent low‑privileged users from executing configuration queries.
  • Segregate the camera’s network or implement firewall rules to restrict external access to its management interfaces, thereby limiting the attack surface.

Generated by OpenCVE AI on September 10, 2026 at 19:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Title Insufficient Permission Validation Exposes Wi‑Fi Configuration in Hikvision Cameras

Thu, 10 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Title Insufficient Permission Validation Allows Low‑Privileged Users to Retrieve Wi‑Fi Configuration from Hikvision Cameras
Weaknesses CWE-284

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Title Insufficient Permission Validation Allows Low‑Privileged Users to Retrieve Wi‑Fi Configuration from Hikvision Cameras
Weaknesses CWE-284

Thu, 10 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description Some Wi-Fi series camera products have insufficient permission validation on certain interfaces, allowing authenticated low-privileged users to obtain device Wi-Fi configuration information through these interfaces.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hikvision

Published:

Updated: 2026-09-10T14:40:09.499Z

Reserved: 2026-09-04T09:24:07.712Z

Link: CVE-2026-85543

cve-icon Vulnrichment

Updated: 2026-09-10T14:39:43.142Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T13:20:32.320

Modified: 2026-09-10T15:17:49.423

Link: CVE-2026-85543

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T19:15:14Z

Weaknesses