High severity7.5NVD Advisory· Published Jun 27, 2022· Updated Jun 17, 2026
CVE-2022-28171
CVE-2022-28171
Description
The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to the insufficient input validation, attacker can exploit the vulnerability to execute restricted commands by sending messages with malicious commands to the affected device.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
15- cpe:2.3:o:hikvision:ds-a71048r-cvs_firmware:*:*:*:*:*:*:*:*Range: <=1.1.4
- cpe:2.3:o:hikvision:ds-a71072r_firmware:*:*:*:*:*:*:*:*Range: <=2.3.8-6
- cpe:2.3:o:hikvision:ds-a72048r-cvs_firmware:*:*:*:*:*:*:*:*Range: <=1.1.4
- cpe:2.3:o:hikvision:ds-a72072r_firmware:*:*:*:*:*:*:*:*Range: <=2.3.8-6
- cpe:2.3:o:hikvision:ds-a80316s_firmware:*:*:*:*:*:*:*:*Range: <=2.3.8-6
- cpe:2.3:o:hikvision:ds-a80624s_firmware:*:*:*:*:*:*:*:*Range: <=2.3.8-6
- cpe:2.3:o:hikvision:ds-a81016s_firmware:*:*:*:*:*:*:*:*Range: <=2.3.8-6
- cpe:2.3:o:hikvision:ds-a82024d_firmware:*:*:*:*:*:*:*:*Range: <=2.3.8-6
- hikvision/DS-A71024/48/72R,DS-A80624S,DS-A81016S,DS-A72024/72R,DS-A80316S,DS-A82024Dv5Range: V2.X
- hikvision/DS-A71024/48R-CVS,DS-A72024/48R-CVSv5Range: V1.X
Patches
Vulnerability mechanics
References
3- packetstormsecurity.com/files/173653/Hikvision-Hybrid-SAN-Ds-a71024-SQL-Injection.htmlnvdExploitThird Party AdvisoryVDB Entry
- packetstormsecurity.com/files/170818/Hikvision-Remote-Code-Execution-XSS-SQL-Injection.htmlnvdThird Party AdvisoryVDB Entry
- www.hikvision.com/en/support/cybersecurity/security-advisory/security-vulnerability-in-some-hikvision-hybrid-san-products/nvdVendor Advisory
News mentions
0No linked articles in our index yet.