Impact
The vulnerability in Hikvision Wi‑Fi series cameras originates from insufficient permission validation on certain configuration interfaces. The flaw allows an authenticated user with low privileges to query the device and retrieve its Wi‑Fi configuration data, including SSIDs and passwords. This is an improper access control weakness that can lead to information disclosure. An attacker who can log into the camera could therefore expose sensitive networking credentials, facilitating further network compromise.
Affected Systems
The CVE affects Hikvision Wi‑Fi series cameras. No specific firmware version is enumerated in the advisory, but the linked release notes reference firmware version V5.7.26. Users should review the documentation for affected models and firmware builds.
Risk and Exploitability
The CVSS score of 4.3 reflects moderate severity; the impact is limited to disclosure to authenticated users. EPSS data is not available and the flaw is not currently listed in the CISA KEV catalog, indicating no known widespread exploitation. An attacker must first obtain valid credentials—through credential theft, social engineering, or other means—before they can query the exposed interfaces. Once authenticated, the flaw is trivial to exploit, requiring only a simple request to the unprotected endpoints.
OpenCVE Enrichment