.. / CVE-2021-36260

Exploit for Hikvision IP camera/NVR - Remote Command Execution (CVE-2021-36260)

Description:

Certain Hikvision products contain a command injection vulnerability in the web server due to the insufficient input validation. An attacker can exploit the vulnerability to launch a command injection attack by sending some messages with malicious commands.

Nuclei Template

View the template here CVE-2021-36260.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2021/CVE-2021-36260.yaml
Copy

References:

https://watchfulip.github.io/2021/09/18/Hikvision-IP-Camera-Unauthenticated-RCE.html
https://github.com/Aiminsun/CVE-2021-36260
https://www.hikvision.com/en/support/cybersecurity/security-advisory/security-notification-command-injection-vulnerability-in-some-hikvision-products/
https://therecord.media/experts-warn-of-widespread-exploitation-involving-hikvision-cameras/
https://nvd.nist.gov/vuln/detail/CVE-2021-36260