Home

Description

There is a privilege escalation vulnerability in some Hikvision DVR products. Due to the improper implementation of authentication for the serial port, an attacker with physical access could exploit this vulnerability by connecting to the affected products and gaining access to an unrestricted shell environment.

PUBLISHED Reserved 2025-11-24 | Published 2025-12-19 | Updated 2025-12-19 | Assigner hikvision




MEDIUM: 6.2CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Product status

Versions below V4.30.122_201107 (including V4.30.122_201107)
affected

Versions below V4.30.122_201107 (including V4.30.122_201107)
affected

Credits

Aaron J Jose finder

References

www.hikvision.com/...bilities-in-some-hikvision-nvr-devices/

cve.org (CVE-2025-66173)

nvd.nist.gov (CVE-2025-66173)

Download JSON

Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.