CVE-2021-36260
Hikvision Improper Input Validation
- Published
- Sep 22, 2021
- Updated
- Oct 21, 2025
- Assigning CNA
- hikvision
- Evidence observed
- Oct 25, 2021
Hikvision Improper Input Validation
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HHigh · next 30 days
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability to launch a command injection attack by sending some messages with malicious commands.
Identify hikvision ip and probe for cve-s (CVE-2017-7921, CVE-2022-28171, CVE-2021-36260)
command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability to launch a command injection attack by sending some messages with malicious commands.
CVE-2021-36260
Python exploit for CVE-2021-36260 command injection in Hikvision web servers. Supports safe/unsafe vulnerability verification, remote command execution, and SSH shell access on IoT devices.
the metasploit script(POC) about CVE-2021-36260
海康威视RCE漏洞 批量检测和利用工具
HikvisionExploiter - это Python утилита созданная для автоматизации сканирования и проверки прямого доступа к сети камер Hikvision, нацеленная на поиск уязвимости Web interface версии 3.1.3.150324 + CVE-2021-36260
海康威视RCE漏洞 批量检测和利用工具
Go-based brute-force exploit tool targeting Hikvision cameras vulnerable to CVE-2021-36260, with multi-threaded scanning and configurable timeout/delay parameters.
网络摄像头漏洞扫描工具 | Webcam vulnerability scanning tool
Issues has been disabled for these PoC's, as they are simply PoC, Public Domain and unsupported.
Brute Hikvision CAMS with CVE-2021-36260 Exploit
CVE-2017-7921, CVE-2021-36260 updated 21/01/2026
HikvisionExploiter is a Python-based utility designed to automate exploitation and directory accessibility checks on Hikvision network cameras exploiting the Web interface Version 3.1.3.150324 + CVE-2021-36260 Detection
CVE-2021-36260
cve-2019-11510, cve-2019-19781, cve-2020-5902, cve-2021-1497, cve-2021-20090, cve-2021-22006, cve-2021-22205, cve-2021-26084, cve-2021-26855, cve-2021-26857, cve-2021–26857, cve-2021–26858, cve-2021–26865
bashis · hardware · Oct 25, 2021
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.