HarborGuard / CVE
Back to search
HIGHCVE-2026-3828Published Modified CNA hikvision

CVE-2026-3828: Some Hikvision switch products (discontinued since December 2023) are vulnerable to authenticated remote command execution due to insufficient input validation

Some Hikvision switch products (discontinued since December 2023) are vulnerable to authenticated remote command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution.

Metrics

CVSS v3.1
7.2
Severity
HIGH
Fixed in
Affected Products
3
Affected packages
  • Hikvision / DS-3E1310P-SI
    Versions below V1.2.4_210623 (including V1.2.4_210623)
  • Hikvision / DS-3E1318P-SI
    Versions below V1.2.0_210823 (including V1.2.0_210823)
  • Hikvision / DS-3E1326P-SI
    Versions below V1.2.0_210823 (including V1.2.0_210823)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
References