Hikvision Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Hikvision products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

6

In CISA KEV

2

Beyond CISA KEV

4

Sensor Observed

0

Virtual Patch Available

0

Hikvision KEVs Added by Year

Loading...

6 Hikvision KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2017-7921

An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I Series...

Confirmed In CISA 01 Jun 2026
CVE-2024-58274

Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2024-08-01 allows execution of a command within $( ) in...

High Not in CISA 01 Jun 2026
CVE-2023-53691

Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2023-06-25 allows file upload via /center/api/files directory...

High Not in CISA 01 Jun 2026
CVE-2025-34067

Hikvision Integrated Security Management Platform Remote Command Execution via applyCT Fastjson

High Not in CISA 02 Jul 2025
CVE-2025-34058

Hikvision Streaming Media Management Server Default Credentials and Authenticated Arbitrary File Read

High Not in CISA 01 Jul 2025
CVE-2021-36260

A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the...

Confirmed In CISA 10 Jan 2022

Common Vulnerability Classes (CWE)

  • CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 2
  • CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 1
  • CWE-24 — Path Traversal: '../filedir' 1
  • CWE-287 — Improper Authentication 1
  • CWE-502 — Deserialization of Untrusted Data 1
  • CWE-521 — Weak Password Requirements 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology