Vulnerabilidades em Hikvision
45 resultadosAnálise Vexday
A Hikvision apresenta 31 vulnerabilidades catalogadas, com 4 classificadas como críticas, mas nenhuma sob exploração ativa conhecida no momento. A fraqueza dominante é injeção de comando (CWE-78), típica de produtos de vigilância, com 3 novos registros nos últimos 90 dias indicando atividade de descoberta contínua. O risco permanece moderado dado a ausência de ataques confirmados, embora a natureza crítica de algumas falhas e o perfil de produto (câmeras e NVRs) justifiquem monitoramento prioritário.
CVE-2023-28813HIGHAn attacker could exploit a vulnerability by sending crafted messages to computers installed with this plug-in to modify plug-in parameters,EPSS 0.6%CVE-2022-28173CRITICALThe web server of some Hikvision wireless bridge products have an access control vulnerability which can be used to obtain the admin permissEPSS 0.6%CVE-2024-25063HIGHDue to insufficient server-side validation, a successful exploit of this vulnerability could allow an attacker to gain access to certain URLEPSS 0.6%CVE-2024-47485MEDIUMThere is a CSV injection vulnerability in some HikCentral Master Lite versions. If exploited, an attacker could build malicious data to geneEPSS 0.6%CVE-2025-66176HIGHThere is a Buffer overflow Vulnerability in the device Search and Discovery feature of Hikvision Access Control Products. If exploited, an aEPSS 0.5%CVE-2023-28814CRITICALSome versions of Hikvision's iSecure Center Product have an improper file upload control vulnerability. Due to the improper verification of EPSS 0.5%CVE-2024-47487HIGHThere is a SQL injection vulnerability in some HikCentral Professional versions. This could allow an authenticated user to execute arbitraryEPSS 0.5%CVE-2025-39247HIGHThere is an Access Control Vulnerability in some HikCentral Professional versions. This could allow an unauthenticated user to obtain the adEPSS 0.5%CVE-2024-29947LOWThere is a NULL dereference pointer vulnerability in some Hikvision NVRs. Due to an insufficient validation of a parameter in a message, an EPSS 0.4%CVE-2024-25064MEDIUMDue to insufficient server-side validation, an attacker with login privileges could access certain resources that the attacker should not haEPSS 0.4%CVE-2024-29948LOWThere is an out-of-bounds read vulnerability in some Hikvision NVRs. An authenticated attacker could exploit this vulnerability by sending sEPSS 0.4%CVE-2023-28811HIGHThere is a buffer overflow in the password recovery feature of Hikvision NVR/DVR models. If exploited, an attacker on the same local area neEPSS 0.4%CVE-2025-39245MEDIUMThere is a CSV Injection Vulnerability in some HikCentral Master Lite versions. This could allow an attacker to inject executable commands vEPSS 0.3%CVE-2025-39246MEDIUMThere is an Unquoted Service Path Vulnerability in some HikCentral FocSign versions. This could allow an authenticated user to potentially eEPSS 0.3%CVE-2025-66174MEDIUMThere is an improper authentication vulnerability in some Hikvision DVR products. Due to the improper implementation of authentication for tEPSS 0.3%CVE-2025-66177HIGHThere is a Buffer overflow Vulnerability in the device Search and Discovery feature of Hikvision NVR/DVR/CVR/IPC models. If exploited, an atEPSS 0.3%CVE-2026-61391HIGHThere is a stack-based buffer overflow vulnerability in some Hikvision cameras, which may allow authenticated attackers to cause device malfEPSS 0.3%CVE-2026-1749MEDIUMThere is an Access Control Vulnerability in some HikCentral Professional versions. This could allow an unauthenticated user to obtain the adEPSS 0.3%CVE-2024-47486LOWThere is an XSS vulnerability in some HikCentral Master Lite versions. If exploited, an attacker could inject scripts into certain pages by EPSS 0.3%CVE-2026-57600HIGHInsufficient validation of input parameters in the firmware of some Hikvision cameras allows unauthenticated attackers to retrieve partial sEPSS 0.2%