Description
Some Hikvision intercom products utilize an immutable factory value which should be obtained from local network or physical interaction with the device within their main card, which may allow attackers to forge a legitimate main card, thereby gaining the permission to issue cards.
Published: 2026-09-10
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized card forgery in Hikvision intercom devices
Action: Assess Impact
AI Analysis

Impact

Some Hikvision intercom products incorporate an immutable factory value that should be retrieved from the local network or through physical interaction with the device’s main card. An attacker can acquire this value and use it to forge a legitimate main card, thereby gaining permission to issue cards and authenticate as an authorized user. This vulnerability, associated with CWE-1310 and CWE-798, allows the creation of counterfeit authentication tokens, enabling an attacker to gain unauthorized access to the intercom system and any premises secured by it.

Affected Systems

The affected products are Hikvision intercom devices: DS-KD8003, DS-KD8005, DS-KV6103, DS-KV6113, DS-KV6114, DS-KV6124, DS-KV6133, DS-KV6134, DS-KV8113, DS-KV8114, DS-KV8213, DS-KV8413, and DS-KV9503. No specific firmware or hardware revision details are provided, so any current production unit of these models may be susceptible.

Risk and Exploitability

The CVSS score of 6.1 classifies this issue as moderate. EPSS score is < 1%, indicating a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote or local network‑based, as forging M1 cards requires interaction with the intercom’s authentication interface. An attacker could generate a valid card credential, thereby bypassing normal access controls. The potential impact ranges from unauthorized entry into protected areas to exploitation of the intercom’s control functions.

Generated by OpenCVE AI on September 21, 2026 at 04:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the device firmware to a version where Hikvision has corrected the encryption configuration, if a patch is available from the vendor.
  • If a patch cannot be applied immediately, disable or restrict the M1 card authentication capability via device configuration or by limiting network access to the intercom management interface.
  • Monitor intercom system logs for unexpected or repeated authentication attempts that might indicate forged card usage.
  • Implement network segmentation or firewall rules to limit traffic to the intercom devices to trusted administrative hosts only.

Generated by OpenCVE AI on September 21, 2026 at 04:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
Title Hikvision Intercom Forged Card Authentication Vulnerability

Fri, 18 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-798

Fri, 18 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Description Some Hikvision intercom products utilize an immutable factory value which should be obtained from local network or physical interaction with the device within their main card, which may allow attackers to forge a legitimate main card, thereby gaining the permission to issue cards. The issue is resolved by removing the main card function in the listed fixed versions. Some Hikvision intercom products utilize an immutable factory value which should be obtained from local network or physical interaction with the device within their main card, which may allow attackers to forge a legitimate main card, thereby gaining the permission to issue cards.
Metrics cvssV3_1

{'score': 5.2, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}

cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Fri, 18 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description There is an Improper Encryption Configuration Vulnerability in some Hikvision Intercom Products. This could allow attackers to forge M1 cards. Some Hikvision intercom products utilize an immutable factory value which should be obtained from local network or physical interaction with the device within their main card, which may allow attackers to forge a legitimate main card, thereby gaining the permission to issue cards. The issue is resolved by removing the main card function in the listed fixed versions.

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Hikvision
Hikvision ds-kd8003
Hikvision ds-kd8005
Hikvision ds-kv6103
Hikvision ds-kv6113
Hikvision ds-kv6114
Hikvision ds-kv6124
Hikvision ds-kv6133
Hikvision ds-kv6134
Hikvision ds-kv8113
Hikvision ds-kv8114
Hikvision ds-kv8213
Hikvision ds-kv8413
Hikvision ds-kv9503
Vendors & Products Hikvision
Hikvision ds-kd8003
Hikvision ds-kd8005
Hikvision ds-kv6103
Hikvision ds-kv6113
Hikvision ds-kv6114
Hikvision ds-kv6124
Hikvision ds-kv6133
Hikvision ds-kv6134
Hikvision ds-kv8113
Hikvision ds-kv8114
Hikvision ds-kv8213
Hikvision ds-kv8413
Hikvision ds-kv9503

Thu, 10 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Title Improper Encryption Configuration Enables M1 Card Forgery in Hikvision Intercoms

Thu, 10 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Title Improper Encryption Configuration Enables M1 Card Forgery in Hikvision Intercoms
Weaknesses CWE-310

Thu, 10 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Title Improper Encryption Configuration Allows Forging M1 Cards in Hikvision Intercom Devices

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1310
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Title Improper Encryption Configuration Allows Forging M1 Cards in Hikvision Intercom Devices
Weaknesses CWE-310

Thu, 10 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description There is an Improper Encryption Configuration Vulnerability in some Hikvision Intercom Products. This could allow attackers to forge M1 cards.
References
Metrics cvssV3_1

{'score': 5.2, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Hikvision Ds-kd8003 Ds-kd8005 Ds-kv6103 Ds-kv6113 Ds-kv6114 Ds-kv6124 Ds-kv6133 Ds-kv6134 Ds-kv8113 Ds-kv8114 Ds-kv8213 Ds-kv8413 Ds-kv9503
cve-icon MITRE

Status: PUBLISHED

Assigner: hikvision

Published:

Updated: 2026-09-18T09:39:16.889Z

Reserved: 2026-09-04T09:24:07.712Z

Link: CVE-2026-85544

cve-icon Vulnrichment

Updated: 2026-09-10T14:52:18.492Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T13:20:32.433

Modified: 2026-09-18T10:17:06.593

Link: CVE-2026-85544

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T05:00:14Z

Weaknesses
  • CWE-1310

    Missing Ability to Patch ROM Code

  • CWE-798

    Use of Hard-coded Credentials