Hangzhou Hikvision Digital Technology manufactures a broad range of video surveillance and security appliances, including network cameras, video management systems, and storage devices, with a portfolio spanning numerous product lines that achieve prominence in the global surveillance market. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the direct internet exposure and embedded-system constraints of surveillance hardware. The exposure recurs across product families such as the DS-KH series and concentrates in weakness classes including buffer-boundary violations, improper access control, insufficient authentication, and sensitive-information disclosure—flaws characteristic of networked devices with legacy firmware architectures and limited update velocity. The vendor's disclosures also have a moderate tendency toward confirmed in-the-wild exploitation and CISA cataloging, underscoring the appeal of surveillance infrastructure as an attack vector for reconnaissance and persistence. Defenders should prioritize inventory and network segmentation of Hikvision devices and maintain close awareness of the vendor's security advisories; live exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hangzhou Hikvision Digital Technology Co., Ltd. over time
Of all the CVEs published by Hangzhou Hikvision Digital Technology Co., Ltd. as a CNA, 45.5% affect products that Hangzhou Hikvision Digital Technology Co., Ltd. develops as a vendor.
Of all the CVEs published that affect products developed by Hangzhou Hikvision Digital Technology Co., Ltd., 55.6% are self-published by Hangzhou Hikvision Digital Technology Co., Ltd. as a CNA.
Signals from CVEs in this vendor scope (36 CVEs).
36 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-36260CRITICAL A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability to launch a command | Sep 22, 2021 | 9.8 | 99 | YES | YES |
CVE-2017-7921CRITICAL An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I Series V5.2.0 build 140721 to V5.4.0 Bui | May 6, 2017 | 9.8 | 99 | YES | YES |
CVE-2023-6895CRITICAL A vulnerability was found in Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK). It has been declared as critical. This vulnerability affects unknown code of the fi | Dec 17, 2023 | 9.8 | 85 | NO | YES |
CVE-2014-4880HIGH Buffer overflow in Hikvision DVR DS-7204 Firmware 2.2.10 build 131009, and other models and versions, allows remote attackers to execute arbitrary code via an RTSP PLAY request wit | Dec 8, 2014 | 7.5 | 80 | NO | YES |
CVE-2022-28171CRITICAL The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to the insufficient input validation, attacker can exploit the v | Jun 27, 2022 | 9.8 | 69 | NO | YES |
CVE-2023-6893HIGH A vulnerability was found in Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK) and classified as problematic. Affected by this issue is some unknown functionality | Dec 17, 2023 | 7.5 | 56 | NO | NO |
CVE-2013-4976CRITICAL Hikvision DS-2CD7153-E IP Camera has security bypass via hardcoded credentials | Dec 27, 2019 | 9.8 | 54 | NO | YES |
CVE-2013-4977HIGH Buffer overflow in the RTSP Packet Handler in Hikvision DS-2CD7153-E IP camera with firmware 4.1.0 b130111 (Jan 2013), and possibly other devices, allows remote attackers to cause | Mar 3, 2014 | 10.0 | 49 | NO | YES |
CVE-2013-4975HIGH Hikvision DS-2CD7153-E IP Camera has Privilege Escalation | Dec 27, 2019 | 8.8 | 45 | NO | YES |
CVE-2025-66176HIGH There is a Buffer overflow Vulnerability in the device Search and Discovery feature of Hikvision Access Control Products. If exploited, an attacker on the same local area network ( | Jan 13, 2026 | 8.8 | 34 | NO | NO |
Signals from CVEs in this vendor scope (36 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hangzhou Hikvision Digital Technology Co., Ltd..
Media articles that mention a CVE ID that affects a product developed by Hangzhou Hikvision Digital Technology Co., Ltd. — matched by CVE ID, not by vendor name.