VYPR

Hikvision

by Hikvision

CVEs (2)

  • CVE-2021-36260CriKEVSep 22, 2021
    risk 0.87cvss 9.8epss 1.00

    A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability to launch a command injection attack by sending some messages with malicious commands.

  • CVE-2026-32684LowMay 12, 2026
    risk 0.19cvss 2.9epss 0.00

    The application does not impose strict enough restrictions on directory access permissions, posing a risk that other malicious applications could obtain sensitive information.