Home

Description

There is a Stack overflow Vulnerability in the device Search and Discovery feature of Hikvision NVR/DVR/CVR/IPC models. If exploited, an attacker on the same local area network (LAN) could cause the device to malfunction by sending specially crafted packets to an unpatched device.

PUBLISHED Reserved 2025-11-24 | Published 2026-01-13 | Updated 2026-01-13 | Assigner hikvision




HIGH: 8.8CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Product status

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Build date before 250807
affected

Versions below V5.7.13_230822 (including V5.7.13_230822)
affected

Versions below V5.7.13_230822 (including V5.7.13_230822)
affected

Versions below V5.7.13_230822 (including V5.7.13_230822)
affected

Versions below V5.7.13_230822 (including V5.7.13_230822)
affected

Versions below V5.7.210_240826 (including V5.7.210_240826)
affected

Versions below V5.7.210_240826 (including V5.7.210_240826)
affected

Versions below V5.7.21_240814 (including V5.7.21_240814)
affected

Versions below V5.7.7build241203 (including V5.7.7build241203)
affected

Versions below V5.7.7build241203 (including V5.7.7build241203)
affected

Versions below V5.7.23_241015 (including V5.7.23_241015)
affected

Versions below V5.7.23_241015 (including V5.7.23_241015)
affected

Versions below V5.7.23_241015 (including V5.7.23_241015)
affected

Versions below V5.7.23_241015 (including V5.7.23_241015)
affected

Versions below V5.7.23_241015 (including V5.7.23_241015)
affected

Versions below V5.7.23_241015 (including V5.7.23_241015)
affected

Credits

Angel Lozano Alcazar finder

Pedro Guillen Nuñez finder

References

www.hikvision.com/...erabilities-in-some-hikvision-products/

cve.org (CVE-2025-66177)

nvd.nist.gov (CVE-2025-66177)

Download JSON

Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.