{"id":"CVE-2026-85544","title":"Some Hikvision intercom products utilize an immutable factory value which should be obtained from local network or physical interaction with the device within their main card, which may allow attackers to forge a legitimate main card, th…","summary":"Some Hikvision intercom products utilize an immutable factory value which should be obtained from local network or physical interaction with the device within their main card, which may allow attackers to forge a legitimate main card, th…","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","cwe":["CWE-798","CWE-1310"],"vendor":"Hikvision","product":"DS-KV9503","affected":["DS-KV9503 V2.3.13 and the versions prior to it","DS-KV6113 V3.7.0 and the versions prior to it","DS-KV6103 V3.7.0 and the versions prior to it","DS-KV6133 V3.7.0 and the versions prior to it","DS-KV8113 V3.7.0 and the versions prior to it","DS-KV8213 V3.7.0 and the versions prior to it","DS-KV8413 V3.7.0 and the versions prior to it","DS-KD8003 V3.7.1 and the versions prior to it","DS-KD8005 V3.10.0 and the versions prior to it","DS-KV6114 V3.9.0 and the versions prior to it","DS-KV6124 V3.9.0 and the versions prior to it","DS-KV6134 V3.9.0 and the versions prior to it","DS-KV8114 V3.11.0 and the versions prior to it"],"published":"2026-09-10","updated":"2026-09-18","sourceUpdated":"2026-09-18T10:17:06.593","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-85544","references":[{"url":"https://www.hikvision.com/en/support/cybersecurity/security-advisory/security-vulnerabilities-in-some-hikvision-intercom-products","label":"hsrc@hikvision.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-10T14:51:42.740079Z"},"epss":0.00148,"epssPercentile":0.04346,"ingestedAt":"2026-09-14T05:33:55.322Z","slug":"CVE-2026-85544","body":"## Overview\n\nSome Hikvision intercom products utilize an immutable factory value which should be obtained from local network or physical interaction with the device within their main card, which may allow attackers to forge a legitimate main card, thereby gaining the permission to issue cards.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":33.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":206692,"id":"CVE-2026-85544","ts":1789724359722,"field":"cvss","old":"5.2","new":"6.1"}]}