HIGHCVE-2026-3828Published Modified CNA hikvision
CVE-2026-3828: Some Hikvision switch products (discontinued since December 2023) are vulnerable to authenticated remote command execution due to insufficient input validation
Some Hikvision switch products (discontinued since December 2023) are vulnerable to authenticated remote command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution.
Metrics
- CVSS v3.1
- 7.2
- Severity
- HIGH
- Fixed in
- —
- Affected Products
- 3
Affected packages
- Hikvision / DS-3E1310P-SIVersions below V1.2.4_210623 (including V1.2.4_210623)
- Hikvision / DS-3E1318P-SIVersions below V1.2.0_210823 (including V1.2.0_210823)
- Hikvision / DS-3E1326P-SIVersions below V1.2.0_210823 (including V1.2.0_210823)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HReferences