KEVIntel
9.8
CVSS
Critical

CVE-2021-36260

PUBLISHED

A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the...

Exploited in the wild Remote Low complexity No user interaction
Vendor
Hikvision
Product
n/a
Published
Sep 22, 2021
EPSS

Description

A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability to launch a command injection attack by sending some messages with malicious commands.

cisa nuclei_scanner metasploit

CVSS scores

CVSS v3.1 9.8 Critical

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2.0 9.3

AV:N/AC:M/Au:N/C:C/I:C/A:C

Exploitation status

Exploited in the wild

Recorded 2022-01-10 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
Yes
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Jan 10, 2022
CISA Jan 10, 2022

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

hikvision_cve_2021_36260_blind

metasploit · Created Unknown

Metasploit module for CVE-2021-36260

Cuerz/CVE-2021-36260

github · Created 2022-08-03 17:27:59 UTC · 149 stars

海康威视RCE漏洞 批量检测和利用工具

TaroballzChen/CVE-2021-36260-metasploit

github · Created 2021-11-03 08:11:49 UTC · 16 stars

the metasploit script(POC) about CVE-2021-36260

Aiminsun/CVE-2021-36260

github · Created 2021-10-27 15:51:12 UTC · 266 stars

command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability to launch a command injection attack by sending some messages with malicious commands.

rabbitsafe/CVE-2021-36260

github · Created 2021-10-18 06:40:48 UTC · 16 stars

CVE-2021-36260

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Added to KEVIntel

  • Detected by Nuclei

  • Detected by Metasploit