CVE-2026-0709

7.2

Hikvision · Wireless Access Points

Certain Hikvision Wireless Access Points are susceptible to authenticated arbitrary command execution resulting from improper input validation.

Executive summary

A high-severity command execution vulnerability in Hikvision Wireless Access Points allows authenticated attackers to gain complete control over affected devices.

Vulnerability

This flaw involves insufficient input validation within the device management interface. An attacker who has obtained valid administrative credentials can execute arbitrary commands on the underlying operating system.

Business impact

Successful exploitation of this vulnerability permits an attacker to achieve full system compromise, potentially leading to unauthorized network access, data interception, or the use of the device as a pivot point for further lateral movement. With a CVSS score of 7.2, this vulnerability represents a significant risk to network integrity, particularly for devices deployed in critical infrastructure or enterprise environments.

Remediation

Immediate Action: Review the official Hikvision security advisory for firmware update availability and apply the necessary patches to all affected access points immediately.

Proactive Monitoring: Monitor device access logs for unusual login patterns or attempts to execute system-level commands that deviate from standard administrative operations.

Compensating Controls: Restrict access to the device management interface to trusted management IP addresses only and ensure that administrative credentials are rotated regularly to limit the potential for unauthorized access.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the severity of potential command execution, organizations should prioritize auditing their Hikvision infrastructure to identify affected models. Administrators must apply vendor-supplied firmware updates as soon as they become available to neutralize the threat of unauthorized command execution.

More Hikvision CVEs

Sources

Originally found and disclosed by exzettabyte, per the CVE Program record.