Over 80,000 Hikvision Surveillance Cameras Remain Vulnerable to Critical Command Injection Flaw Nearly a Year After Patch Release

Nearly a year after cybersecurity researchers and software developers first disclosed a severe, highly exploitable command injection flaw affecting tens of thousands of video surveillance devices worldwide, more than 80,000 Hikvision cameras remain unpatched and exposed to potential malicious interference. The vulnerability, officially cataloged as CVE-2021-36260, carries a maximum severity rating of 9.8 out of 10 on the National Vulnerability Database (NVD) scale managed by the National Institute of Standards and Technology (NIST). Despite the critical nature of the security gap and the availability of official vendor firmware updates, thousands of enterprises, government entities, and private organizations across more than 100 countries continue to operate vulnerable hardware, creating a sprawling, global attack surface for sophisticated threat actors.
The persistence of this vulnerability highlights deep-seated structural issues within the Internet of Things (IoT) manufacturing sector, where legacy architecture, lack of automated update mechanisms, and lax consumer configuration habits intersect to create enduring cyber security risks. Security analysts tracking the exploitation landscape have observed active reconnaissance and dark web collaboration targeting these specific devices, raising alarms among national security agencies and enterprise risk managers alike.
Understanding the Flaw: Anatomy of CVE-2021-36260
The security flaw originates in the web server component of a wide range of Hikvision IP cameras. Specifically, CVE-2021-36260 is classified as a command injection vulnerability that arises from improper neutralization of special elements used in a command. By sending specially crafted messages containing malicious command sequences to the vulnerable web server, an unauthenticated, remote attacker can execute arbitrary commands on the underlying operating system of the affected camera.
Because surveillance cameras typically operate with elevated privileges to manage video feeds, storage operations, and network configurations, a successful exploit grants the attacker total control over the device. This includes the ability to intercept video streams, alter recording logs, pivot deeper into the host organization’s internal corporate network, or conscript the camera into a sprawling botnet designed to launch distributed denial-of-service (DDoS) attacks.
Hikvision, formally known as Hangzhou Hikvision Digital Technology Co., Ltd., is a massive, state-backed video surveillance manufacturer headquartered in Zhejiang, China. Its products command a significant share of the global commercial security market, deployed across critical infrastructure sectors, municipal traffic management systems, retail environments, educational institutions, and residential properties worldwide. Consequently, the discovery of a pre-authentication remote code execution vulnerability in such pervasive hardware triggered an immediate, high-priority alert across the international cybersecurity community upon its disclosure in the fall of 2021.
Chronology and Timeline of the Vulnerability
The lifecycle of CVE-2021-36260 illustrates the prolonged window of exposure that often characterizes enterprise IoT vulnerabilities:
- September 2021: Independent security researcher Watchful IP discovers the critical command injection vulnerability in Hikvision IP cameras and privately reports the finding to the manufacturer through coordinated vulnerability disclosure channels.
- September 18, 2021: Hikvision officially acknowledges the security flaw and releases emergency firmware updates designed to patch CVE-2021-36260 across the affected camera models.
- October 2021: NIST formally publishes CVE-2021-36260, assigning the vulnerability a critical CVSS base score of 9.8. Public awareness spikes as technical details and proof-of-concept exploit scripts begin circulating within security research circles.
- Late 2021 to Spring 2022: Automated vulnerability scanners and threat actors begin aggressively scanning the public-facing internet using tools like Shodan and Censys to map unpatched Hikvision devices. Intelligence reports indicate early exploitation attempts in the wild.
- Summer 2022: Threat intelligence firm Cyfirma publishes updated telemetry revealing that more than 80,000 Hikvision cameras remain unpatched globally. Researchers observe threat actors—including Russian-speaking cybercriminal syndicates—actively discussing exploitation strategies and trading leaked administrative credentials on dark web forums.
Geopolitical Dimensions and Targeted Threats
The global footprint of Hikvision equipment has long intertwined commercial security technology with international geopolitics. In 2019, the United States Federal Communications Commission (FCC) designated Hikvision as an entity posing "an unacceptable risk to U.S. national security," leading to strict prohibitions on federal procurement of its equipment. Similar regulatory scrutiny has unfolded in other Western jurisdictions over concerns regarding data privacy, state surveillance integration, and supply chain integrity.
With tens of thousands of these devices remaining unpatched nearly a year after remediation tools were made available, intelligence analysts are increasingly concerned about potential exploitation by advanced persistent threat (APT) groups. While definitive attribution for historical attacks remains challenging due to the obfuscated nature of cyber operations, security researchers emphasize that state-backed actors frequently leverage unpatched IoT infrastructure for espionage, reconnaissance, and pre-positioning within critical networks.
Reports from threat intelligence providers suggest that Chinese state-sponsored groups—such as entities tracked as MISSION2025, APT41, and APT10—alongside various Russian cybercrime syndicates and unknown regional threat actors, maintain the capability and motive to exploit vulnerable surveillance cameras. In a conflict or heightened geopolitical crisis, compromising a nation’s physical security network can provide adversaries with invaluable situational awareness, internal network access points, or the ability to disrupt municipal and corporate operations.
Systemic Vulnerabilities Across the IoT Ecosystem
While the failure to apply available patches points to operational oversight by end users, cybersecurity experts argue that blaming organizations alone oversimplifies a much larger, systemic crisis within the Internet of Things manufacturing and deployment model.
David Maynor, senior director of threat intelligence at Cybrary, points out that Hikvision devices have historically suffered from compounding security hurdles. "Their product contains easy-to-exploit systemic vulnerabilities or worse, uses default credentials," Maynor explains. "There is no good way to perform forensics or verify that an attacker has been excised. Furthermore, we have not observed any change in Hikvision’s posture to signal an increase in security within their development cycle."
Unlike traditional desktop computers or modern mobile operating systems that feature streamlined, automated background updates, IoT hardware often operates as a digital "black box." Paul Bischoff, a privacy advocate and security researcher with Comparitech, highlights the inherent friction in securing connected physical devices.
"IoT devices like cameras aren’t always as easy or straightforward to secure as an app on your phone," Bischoff notes. "Updates are not automatic; users need to manually download and install them, and many users might never get the message. Furthermore, IoT devices might not give users any indication that they’re unsecured or out of date. Whereas your phone will alert you when an update is available and likely install it automatically the next time you reboot, IoT devices do not offer such conveniences."
This absence of user-friendly maintenance architecture is further exacerbated by human error and configuration inertia. Many organizations deploy surveillance cameras during construction or initial facility setup and subsequently adopt a "set-and-forget" mentality. Compounding the risk, numerous devices are initialized using factory-default administrator credentials—such as simple alphanumeric strings or blank passwords—which are rarely modified by installers or property managers. When combined with exposure to the public internet via Universal Plug and Play (UPnP) or manual port forwarding, these default settings allow automated scanning tools to discover and compromise devices within seconds.
Implications and Mitigation Strategies for Affected Organizations
The continued existence of tens of thousands of exploitable Hikvision cameras underscores a pressing need for a paradigm shift in how organizations manage physical security convergence. As traditional closed-circuit television (CCTV) systems are increasingly integrated into Internet Protocol (IP) networks, physical security devices effectively become computer nodes that demand the same rigorous patch management, network segmentation, and identity governance applied to enterprise servers and workstations.
Cybersecurity agencies, including the Cybersecurity and Infrastructure Security Agency (CISA) and international counterparts, repeatedly urge organizations to implement comprehensive asset discovery protocols to identify all connected IoT and operational technology (OT) assets. Key mitigation steps recommended by security professionals include:
- Immediate Firmware Updates: Organizations utilizing Hikvision equipment must immediately consult official vendor channels, verify device model numbers, and apply the latest available firmware patches corresponding to CVE-2021-36260.
- Network Segmentation: Surveillance cameras and other IoT peripherals should be isolated onto dedicated, heavily restricted Virtual Local Area Networks (VLANs). These networks must be firewalled from internal corporate resources and prohibited from communicating directly with the public internet unless routed through secure, encrypted Virtual Private Networks (VPNs).
- Credential Hardening: All default factory usernames and passwords must be immediately replaced with strong, unique passphrases managed through enterprise password vaults. Shared administrative accounts should be disabled in favor of role-based access control.
- Attack Surface Reduction: Organizations should audit external perimeter defenses to ensure that camera management interfaces and streaming ports are not directly exposed to the public internet. Utilizing search engines like Shodan or Censys to periodically scan external IP blocks can help security teams identify accidental exposures.
- Enhanced Monitoring: Security Operations Centers (SOCs) should integrate network traffic analysis tools capable of detecting anomalous outbound connections, unauthorized login attempts, and unusual command-line executions originating from IoT hardware.
As cyber threats continue to evolve and adversaries increasingly target the path of least resistance within enterprise networks, the prolonged neglect of fundamental hygiene for connected physical devices remains an acute vulnerability. Until manufacturers embrace mandatory automated updating frameworks and organizations treat IoT security with the same gravity as core IT infrastructure, the legacy of flaws like CVE-2021-36260 will continue to pose a pervasive threat to global digital safety.






