Hikvision has 4 CVEs on record. 3 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 6.6 (medium).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.6
- Publish → KEV
- —
- Last 90 days
- 3 prev 0
Weakness classes
Products
- DS-KV9503 1
- HikCentral Access Control 1
- Wi-Fi series camera 1
- ds-k1t331_firmware 1
Worst active — by depth score
CVE-2025-66176High· 8.8There is a Buffer overflow Vulnerability in the device Search and Discovery feature of Hikvision Access Control Products48CVE-2026-85545High· 7.1There is an Vulnerability in some HikCentral Access Control versions39CVE-2026-85543Medium· 4.3Some Wi-Fi series camera products have insufficient permission validation on certain interfaces, allowing authenticated low-privileged users to obtain device Wi-Fi configuration information through these interfaces.36CVE-2026-85544Medium· 6.1Some Hikvision intercom products utilize an immutable factory value which should be obtained from local network or physical interaction with the device within their main card, which may allow attackers to forge a legitimate main card, th…34
Hikvision vulnerabilities
CVEs affecting Hikvision, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2026-85544Medium· 6.1Some Hikvision intercom products utilize an immutable factory value which should be obtained from local network or physical interaction with the device within their main card, which may allow attackers to forge a legitimate main card, th…
Some Hikvision intercom products utilize an immutable factory value which should be obtained from local network or physical interaction with the device within their main card, which may allow attackers to forge a legitimate main card, th…
CVE-2026-85543Medium· 4.3PoCSome Wi-Fi series camera products have insufficient permission validation on certain interfaces, allowing authenticated low-privileged users to obtain device Wi-Fi configuration information through these interfaces.
Some Wi-Fi series camera products have insufficient permission validation on certain interfaces, allowing authenticated low-privileged users to obtain device Wi-Fi configuration information through these interfaces.
CVE-2026-85545High· 7.1There is an Vulnerability in some HikCentral Access Control versions
There is an Vulnerability in some HikCentral Access Control versions. Authenticated low-privilege users can invoke API interfaces that their role is not authorized to access.
CVE-2025-66176High· 8.8There is a Buffer overflow Vulnerability in the device Search and Discovery feature of Hikvision Access Control Products
There is a Buffer overflow Vulnerability in the device Search and Discovery feature of Hikvision Access Control Products. If exploited, an attacker on the same local area network (LAN) could cause the device to malfunction by sending spe…