Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/mk-ultra-project-monarch/cve-2017-7921-writeup-2026
IoT SecurityVulnerability AnalysisExploitationWeb Application ExploitationPapers & ResearchLearning & Education
GitHubmk-ultra-project-monarch/cve-2017-7921-writeup-2026

CVE-2017-7921-Writeup-2026

Vulnerability research write-up on CVE-2017-7921 — a critical unauthenticated auth bypass in Hikvision IP cameras/DVRs/NVRs, covering root cause, exploitation path, detection, and remediation.

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository
1362 months agoNot yet reviewed

CVE-2017-7921 — Hikvision IP Camera / DVR / NVR

Improper Authentication — Privilege Escalation via Crafted Query Parameter

CVE IDCVE-2017-7921
Vulnerability ClassCWE-287: Improper Authentication
CVSS v3.0 Base Score10.0 (Critical) — AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS v2.0 Score7.5 (High) — AV:N/AC:L/Au:N/C:P/I:P/A:P
Disclosure Date2017 (ICS-CERT Advisory ICSA-17-124-01)
VendorHikvision Digital Technology Co., Ltd.
StatusPatched — Hikvision released corrected firmware; unpatched and "grey-market" devices remain exposed
PoC / Exploit AuthorJared Brits (K3ysTr0K3R)
Write-up AuthorMK-ULTRA (github.com/MK-ULTRA-project-monarch)

1. Executive Summary

CVE-2017-7921 is a critical improper-authentication vulnerability affecting the web server component of firmware on a wide range of Hikvision network cameras, DVRs, and NVRs. The flaw allows a remote, unauthenticated attacker to bypass the device's login mechanism entirely by appending a specially crafted, statically defined query parameter to specific HTTP request paths. Because the authentication check trusts this parameter rather than validating a session or credential set, any request carrying it is treated as though it originated from a privileged internal process.

Successful exploitation grants full administrative access to the device web interface, including live and recorded video streams, device configuration, user account data, and — on many firmware branches — the ability to download the full device configuration file, which itself contains weakly encrypted stored credentials. The vulnerability requires no user interaction, no prior authentication, and no non-standard network position, which combined with the scale of Hikvision's install base has made it a persistent target for botnet recruitment (e.g., Reaper/IoTroop-family activity) and surveillance-feed harvesting since disclosure.

2. Affected Products

The vulnerability was confirmed across multiple Hikvision product families running firmware branches predating the 2017 security patch. Representative affected lines include:

  • DS-2CD2xx2F-I series — firmware V5.2.0 (build 140721) through V5.4.0 (build 160530)
  • DS-2CD2xx0F-I series — firmware V5.2.0 (build 140721) through V5.4.0 (build 160401)
  • DS-2CD2xx2FWD series — firmware V5.3.1 (build 150410) through V5.4.4 (build 161125)
  • DS-2CD4x2xFWD series — firmware V5.2.0 (build 140721) through V5.4.0 (build 160414)
  • DS-2CD4xx5 series — firmware V5.2.0 (build 140721) through V5.4.0 (build 160421)
  • DS-2DFx PTZ series — firmware V5.2.0 (build 140805) through V5.4.5 (build 160928)
  • DS-2CD63xx series and select NVR/DVR product lines sharing the same web-server codebase

Hikvision also flagged an ongoing complication specific to this CVE: a large population of "grey-market" devices sold outside authorized distribution channels run modified, non-Hikvision firmware. Standard firmware updates do not reliably remediate these units, and in some cases revert the interface rather than patch it.

3. Technical Analysis

3.1 Root Cause

Standard Hikvision device authentication is built on HTTP Basic/Digest auth guarding the web management interface. In vulnerable firmware, however, a subset of internal request-handling endpoints contain a secondary, undocumented authentication path intended for internal/debug use. This path does not perform a credential lookup — it inspects the request for the presence of a fixed, hardcoded token and, if found, treats the request as pre-authenticated, bypassing the normal role-based access control (RBAC) checks entirely.

The token is a Base64-encoded representation of a static default credential pair embedded in the firmware itself. Because it is a constant rather than a derived session value, it is identical across every vulnerable device regardless of the administrator password actually configured on that unit — changing the admin password does not mitigate the vulnerability.

3.2 Exploitation Path

At a high level, exploitation follows this sequence:

  1. The attacker identifies a reachable Hikvision device (commonly via Shodan/Censys fingerprinting of the exposed web management port).
  2. A crafted HTTP GET request is sent to a known vulnerable endpoint with the static authentication token appended as a query parameter, rather than presenting a username/password.
  3. The vulnerable firmware's request handler validates the token instead of a session or credential, and services the request with administrative privilege.
  4. The attacker can now enumerate and modify device configuration, view live/recorded streams, and — on affected builds — retrieve the full configuration export, which stores additional account credentials under weak, static-key encryption that can be reversed offline.

No memory corruption, buffer overflow, or client-side interaction is involved; the entire attack is a single crafted, stateless HTTP request, which is what makes it trivially scriptable and scanner-friendly.

3.3 Why It Persists

Three factors account for the CVE's unusually long tail of real-world exposure:

  • Devices are frequently deployed once and never re-visited for firmware updates, especially in residential and small-business installs.
  • Grey-market units running unauthorized firmware often cannot be patched through official channels at all.
  • The vulnerability is index-friendly — because exploitation is a single unauthenticated HTTP request, mass scanning tools can enumerate vulnerable hosts across the entire IPv4 space cheaply, which is precisely how it has been leveraged for IoT botnet recruitment.

4. Impact

MetricImpact
ConfidentialityComplete — live/recorded video, device configuration, and stored (weakly encrypted) credentials are exposed.
IntegrityComplete — attacker can modify device configuration, user accounts, and stream settings.
AvailabilityComplete — attacker can disable recording, reboot, or otherwise disrupt device operation.
ScopeChanged (CVSS v3) — compromise of the device frequently enables pivoting into the broader network or recruitment into distributed botnets.

5. Detection & Indicators

  • Unauthenticated HTTP GET requests to device management endpoints containing an appended, non-user query parameter resembling a Base64-encoded credential string.
  • Configuration export requests (e.g., device config/backup file retrieval) originating from sessions that never completed standard Basic/Digest authentication.
  • Unexpected outbound connections from camera/NVR devices consistent with botnet check-in traffic (a common secondary indicator once a device has been mass-exploited).
  • Vendor and third-party detection content: Check Point IPS signature CPAI-2017-0876, Tenable.ot plugin tenable_ot_hikvision_CVE-2017-7921.nasl, and CISA/ICS-CERT advisory ICSA-17-124-01.

6. Remediation

Download Tool