Vulnerabilidades em hikvision
48 resultadosAnálise Vexday
Hikvision apresenta 8 vulnerabilidades conhecidas na base, com 2 classificadas como críticas, porém nenhuma sob exploração ativa no momento. A fraqueza dominante (CWE-284 - Improper Access Control) sugere problemas estruturais em controle de acesso, exigindo atenção em políticas de permissões. Sem atividade de ataque recente e sem novos CVEs nos últimos 90 dias, o risco permanece contido mas requer monitoramento contínuo da superfície de controle de acesso.
CVE-2025-39246MEDIUMThere is an Unquoted Service Path Vulnerability in some HikCentral FocSign versions. This could allow an authenticated user to potentially eEPSS 0.3%CVE-2026-1749MEDIUMThere is an Access Control Vulnerability in some HikCentral Professional versions. This could allow an unauthenticated user to obtain the adEPSS 0.3%CVE-2024-47486LOWThere is an XSS vulnerability in some HikCentral Master Lite versions. If exploited, an attacker could inject scripts into certain pages by EPSS 0.3%CVE-2025-66173MEDIUMThere is a privilege escalation vulnerability in some Hikvision DVR products. Due to the improper implementation of authentication for the sEPSS 0.2%CVE-2026-85543MEDIUMSome Wi-Fi series camera products have insufficient permission validation on certain interfaces, allowing authenticated low-privileged usersEPSS 0.2%CVE-2026-85545HIGHThere is an Vulnerability in some HikCentral Access Control versions. Authenticated low-privilege users can invoke API interfaces that theirEPSS 0.2%CVE-2026-85544MEDIUMSome Hikvision intercom products utilize an immutable factory value which should be obtained from local network or physical interaction withEPSS 0.1%CVE-2026-32684LOWThe application does not impose strict enough restrictions on directory access permissions, posing a risk that other malicious applications EPSS 0.1%