Thursday, September 24, 2026

Hikvision Wireless AP Flaw Could Let Attackers Run Arbitrary Commands

Hikvision has disclosed a high-severity command execution vulnerability affecting multiple wireless access point models, potentially allowing authenticated attackers to execute arbitrary commands on affected devices.

The company released an advisory on January 30, 2026, detailing the security flaw and urging customers to apply patches immediately.

Vulnerability Details

The vulnerability, tracked as CVE-2026-0709, stems from insufficient input validation in Hikvision’s wireless access point firmware.

Attackers with valid credentials can exploit this flaw by sending specially crafted packets containing malicious commands to compromised devices, thereby bypassing security controls and executing commands.

ModelVulnerable VersionPatched VersionCVE ID
DS-3WAP521-SIV1.1.6303 build250812 and earlierV1.1.6601 build251223CVE-2026-0709
DS-3WAP522-SIV1.1.6303 build250812 and earlierV1.1.6601 build251223CVE-2026-0709
DS-3WAP621E-SIV1.1.6303 build250812 and earlierV1.1.6601 build251223CVE-2026-0709
DS-3WAP622E-SIV1.1.6303 build250812 and earlierV1.1.6601 build251223CVE-2026-0709
DS-3WAP623E-SIV1.1.6303 build250812 and earlierV1.1.6601 build251223CVE-2026-0709
DS-3WAP622G-SIV1.1.6303 build250812 and earlierV1.1.6601 build251223CVE-2026-0709

The attack requires network access and valid authentication credentials but does not require user interaction.

Hikvision assigned the vulnerability a CVSS v3.1 base score of 7.2, which is classified as high severity.

The CVSS vector (AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A: H) indicates the flaw is remotely exploitable, has low attack complexity, and requires high-level privileges.

The vulnerability impacts the confidentiality, integrity, and availability of affected systems.

This vulnerability impacts six wireless access point models from Hikvision’s DS-3WAP series. All devices running firmware version V1.1.6303 build 250812 or earlier are vulnerable to exploitation.

The affected models include DS-3WAP521-SI, DS-3WAP522-SI, DS-3WAP621E-SI, DS-3WAP622E-SI, DS-3WAP623E-SI, and DS-3WAP622G-SI.

Hikvision released a patched firmware version, V1.1.6601 build 251223, addressing the vulnerability.

Organizations operating affected access points should prioritize updating to this version immediately. Patches are available for download and deployment through Hikvision’s official support portal.

The vulnerability was discovered and reported by independent security researcher exzettabyte to Hikvision’s Security Response Center (HSRC).

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Exvicy ClickFix Malware-as-a-Service Copies ErrTraffic to Hijack WordPress Sites

A new Malware-as-a-Service platform, Exvicy, is actively abusing compromised...

HPE Networking Analytics Engine Flaws Let Attackers Gain Root Access

Hewlett Packard Enterprise (HPE) has announced security updates for...

Cybercriminals Abandon Domains but Keep the Hosting Networks Behind Malware Campaigns

Cybercriminals are rapidly rotating lure domains, cloud storage buckets...

SolarWinds Observability Flaws Let Unauthenticated Attackers Execute Remote Code

SolarWinds has released SolarWinds Observability Self-Hosted version 2026.2.3 to...

Microsoft Warns of EvilTokens AI Phishing Service Hijacking Thousands of Accounts

Microsoft has warned that the EvilTokens phishing-as-a-service platform has...

Related Articles

Recent News