logo

Hikvision Wireless Access Points Vulnerability Enables Malicious Command Execution

ID: cd86896d-63fc-5b87-97b3-74a48b032a46

STIX ID: report--cd86896d-63fc-5b87-97b3-74a48b032a46

Feed Name: cybersecurityNews.com

Threat Score
72/100

Date Published: 2026-02-03

Date Updated: 2026-04-21

Author: Abinaya

...
...

A high-severity authenticated command-execution vulnerability (CVE-2026-0709, CVSS 7.2) affects multiple Hikvision WAP models running firmware V1.1.6303 build250812 and earlier; attackers with valid credentials can send crafted packets to execute arbitrary commands. Hikvision released patched firmware (V1.1.6601 build 251223); organizations are advised to update immediately, enforce strong authentication, rotate credentials, and apply network segmentation as interim mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.