CVE-2026-16843

Hikvision · Wireless Access Points (DS-3WAP series)

Certain Hikvision wireless access points contain a command execution vulnerability due to insufficient input validation that can be triggered by an authenticated user.

Executive summary

Authenticated command execution in Hikvision wireless access points permits unauthorized system control, presenting a critical risk to network infrastructure.

Vulnerability

This is a command execution vulnerability resulting from insufficient input validation. The attack requires the user to have high-level administrative privileges on the device.

Business impact

An attacker with administrative access can execute arbitrary commands on the affected hardware, leading to full system compromise. Given the CVSS score of 7.2, this vulnerability could allow an attacker to pivot into the internal network or disrupt critical communication services.

Remediation

Immediate Action: Apply the vendor-provided firmware updates immediately to address the input validation flaw.

Proactive Monitoring: Monitor device logs for anomalous command execution patterns or unauthorized changes to system configurations.

Compensating Controls: Restrict administrative access to the management interface of the wireless access points to trusted management networks only.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

All organizations utilizing the identified Hikvision wireless access points must verify their current firmware version and apply the manufacturer update as soon as possible. Securing management interfaces is essential to mitigating the risk of administrative-level exploitation.