Home

Description

Due to insufficient input parameter validation on the interface, authenticated users of certain HIKSEMI NAS products can execute arbitrary commands on the device by crafting specific messages.

PUBLISHED Reserved 2026-01-08 | Published 2026-01-30 | Updated 2026-01-30 | Assigner hikvision




HIGH: 7.2CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Product status

V5.10.10_Build_251126
affected

Credits

Jincheng Wang finder

References

www.hiksemitech.com/...iksemi/support/security-advisory.html

cve.org (CVE-2026-22623)

nvd.nist.gov (CVE-2026-22623)

Download JSON