Hikvision Multiple Products Vulnerability Allows Malicious Users to Escalate Privileges
ID: 3ee6b198-edc1-5960-a068-abf8c0a3609a
STIX ID: report--3ee6b198-edc1-5960-a068-abf8c0a3609a
Feed Name: cybersecurityNews.com
A severe authentication-bypass vulnerability (tracked as CVE-2017-7921) affecting multiple Hikvision IP cameras and NVRs was added to the Known Exploited Vulnerabilities catalog on March 5, 2026. The flaw permits attackers to bypass login, escalate privileges, access live and recorded video, and extract configuration data; CISA has issued a March 26, 2026 remediation deadline and agencies are required to address the issue under BOD 22-01. Administrators are advised to apply vendor mitigations, update firmware, or remove unsupported devices from networks to prevent lateral movement and data exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
