CVE-2026-22623
7.2HIKSEMI · HS-AFS-S1H1
HIKSEMI NAS devices contain an input validation vulnerability that allows authenticated users to execute arbitrary commands by sending specially crafted messages to the interface.
Executive summary
A critical command injection vulnerability in HIKSEMI NAS devices poses a significant risk of full system compromise for authenticated users.
Vulnerability
This vulnerability involves insufficient input parameter validation within the device interface, which permits authenticated users with high privileges to execute arbitrary system commands.
Business impact
Successful exploitation of this flaw allows an attacker to achieve complete control over the affected NAS device, potentially leading to unauthorized data access, modification, or total system disruption. With a CVSS score of 7.2, the vulnerability represents a high risk to organizational security, as it grants attackers the ability to use the device as a pivot point for further lateral movement within the network.
Remediation
Immediate Action: Administrators should review the official HIKSEMI security advisory for firmware updates and apply the latest available version to remediate the command injection flaw.
Proactive Monitoring: Security teams should monitor device access logs for unusual command patterns or unauthorized attempts to access system-level configuration interfaces.
Compensating Controls: Implement strict network segmentation to isolate NAS devices from critical network segments and utilize a Web Application Firewall to filter suspicious traffic directed at the device interface.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the potential for full system compromise, it is imperative that organizations using the HIKSEMI HS-AFS-S1H1 device prioritize the application of vendor patches as they become available. Ensure that administrative access to the NAS interface is restricted to trusted personnel to mitigate the risk posed by the authentication requirement of this vulnerability.
Sources
Originally found and disclosed by Jincheng Wang, per the CVE Program record.