VYPR
researchPublished Oct 8, 2026· 1 source

Hikvision Camera Vulnerability Targeted in Exploitation Attempts

GreyNoise observed a surge in exploitation attempts against CVE-2021-36260, a critical command injection vulnerability in Hikvision products, targeting devices in Ukraine.

GreyNoise has identified a significant rise in scanning and remote code execution (RCE) attempts targeting video surveillance devices, particularly in Ukraine, between September 21 and October 1, 2026. The majority of this observed activity focused on CVE-2021-36260, a critical command injection vulnerability affecting unpatched Hikvision products. This surge in exploitation attempts occurred concurrently with Russian missile and drone strikes in the region, though researchers have not yet established a direct connection between the cyber activity and the physical attacks.

The findings highlight a renewed interest in this older vulnerability, which, if successfully exploited, can allow attackers to gain control over exposed cameras and recording equipment without requiring any form of authentication. However, it is crucial to note that GreyNoise's observations document exploitation *attempts*, not confirmed takeovers or compromises of actual surveillance systems. This distinction is vital for accurately assessing the campaign's true impact and potential objectives.

According to GreyNoise's timeline, initial reconnaissance activities began on September 21, 2026, when an IP address originating from a Ukrainian network initiated connections to service ports without sending any exploit payloads. The exploitation attempts escalated sharply on September 23 and continued through October 1, marking a distinct nine-day surge after a period of minimal comparable activity against Ukraine. A small number of IP addresses were responsible for the bulk of these attempts.

Specifically, four IP addresses were identified as the primary sources of the exploitation attempts. Three of these IPs were associated with PureVPN exit nodes, while the fourth originated from a domestic Ukrainian network. GreyNoise assessed that a single entity likely drove the VPN-related activity, though the connection to the Ukrainian IP address was made with low confidence. The VPN addresses were identified as 195.238.124.178, 195.238.124.181, and 195.238.124.188, all routed through AS56630 in Lithuania. It is important to acknowledge that commercial VPN exits can be used by unrelated individuals, so these indicators should not be solely relied upon as proof of a shared operator.

The observed activity exclusively utilized a publicly available Nuclei template titled "Hikvision IP camera/NVR – Remote Command Execution." The use of such a template strongly suggests automated vulnerability testing rather than the deployment of sophisticated malware or the actual exfiltration of video feeds. GreyNoise's analysis of the command-test nature of the requests further supports this interpretation of automated scanning.

CVE-2021-36260 affects the web server component within specific Hikvision products. The vulnerability stems from inadequate input validation, which allows specially crafted requests containing malicious commands to be passed directly to the device's operating system. NIST has assigned this vulnerability a critical CVSS score of 9.8, underscoring its potential for exploitation over a network without authentication or user interaction.

While this recent surge is notable, it is important to recall that Cybersecurity News previously reported on over 80,000 exposed, vulnerable Hikvision cameras in 2022. This historical data illustrates the persistent exposure problem associated with this flaw, though it does not represent a current count of vulnerable devices. Compromised cameras can indeed reveal sensitive locations and activities, as demonstrated by a January 2024 incident where Ukrainian authorities disabled two cameras that Russian intelligence had allegedly compromised to monitor Kyiv's air defenses and infrastructure.

To mitigate the risks associated with CVE-2021-36260, administrators are strongly advised to identify affected Hikvision models and promptly apply the latest firmware updates, as recommended by CISA. Additionally, restricting public internet access to these devices and segmenting surveillance equipment from critical internal networks can further reduce exposure while updates are being implemented. It is critical to understand that changing default passwords alone will not resolve an unauthenticated command injection vulnerability.

Synthesized by Vypr AI