logo

WiFi Hijack: Hikvision Patches Command Injection in DS-3WAP Access Points

ID: 6a34d150-c3fa-518a-88ba-24e726a0d1ed

STIX ID: report--6a34d150-c3fa-518a-88ba-24e726a0d1ed

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-02-03

Date Updated: 2026-04-23

Author: Ddos

...
...

Hikvision patched a high-severity authenticated command-execution vulnerability (CVE-2026-0709, CVSS 7.2) affecting multiple DS-3WAP series wireless access points (firmware V1.1.6303 build250812 and earlier). The flaw, caused by insufficient input validation, allows an authenticated user to send crafted packets to execute arbitrary commands on the device, enabling interception, lateral movement, or disruption; administrators are urged to update affected devices to V1.1.6601 build251223 immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.