What happened
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation.
Affected versions
Security cameras web server: See original advisory Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
Exploit-DB 50441Hikvision Web Server Build 210702 - Command Injectionbashis2021-10-25VerifiedPoC-in-GitHub · rabbitsafe/CVE-2021-36260CVE-2021-36260★ 17rabbitsafe2021-10-18CandidatePoC-in-GitHub · Aiminsun/CVE-2021-36260command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability to launch a command injection attack by sending some messages with malicious commands.★ 301Aiminsun2021-10-27CandidatePoC-in-GitHub · TaroballzChen/CVE-2021-36260-metasploitthe metasploit script(POC) about CVE-2021-36260★ 20TaroballzChen2021-11-03CandidatePoC-in-GitHub · tuntin9x/CheckHKRCECVE-2021-36260★ 7tuntin9x2021-12-13CandidatePoC-in-GitHub · Cuerz/CVE-2021-36260海康威视RCE漏洞 批量检测和利用工具★ 169Cuerz2022-08-03CandidatePoC-in-GitHub · haingn/HIK-CVE-2021-36260-Exploit★ 1haingn2023-10-22CandidatePoC-in-GitHub · NanoTrash/hikvision_bruteBrute Hikvision CAMS with CVE-2021-36260 Exploit★ 3NanoTrash2024-03-07CandidatePoC-in-GitHub · tamim1089/HikvisionExploiterHikvisionExploiter is a Python-based utility designed to automate exploitation and directory accessibility checks on Hikvision network cameras exploiting the Web interface Version 3.1.3.150324 + CVE-2021-36260 Detection★ 380tamim10892024-07-05CandidatePoC-in-GitHub · aengussong/hikvision_probeIdentify hikvision ip and probe for cve-s (CVE-2017-7921, CVE-2022-28171, CVE-2021-36260)★ 3aengussong2024-11-26CandidatePoC-in-GitHub · shubtheone/CVE-2021-36260-hikvision★ 0shubtheone2026-01-15CandidatePoC-in-GitHub · yanxinwu946/hikvision-unauthenticated-rce-cve-2021-36260海康威视RCE漏洞 批量检测和利用工具★ 3yanxinwu9462026-01-21CandidatePoC-in-GitHub · saaydmr/hikvision-exploiterCVE-2017-7921, CVE-2021-36260 updated 21/01/2026★ 1saaydmr2026-01-21CandidatePoC-in-GitHub · code-msga/HikvisionExploiter_fixedHikvisionExploiter - это Python утилита созданная для автоматизации сканирования и проверки прямого доступа к сети камер Hikvision, нацеленная на поиск уязвимости Web interface версии 3.1.3.150324 + CVE-2021-36260★ 0code-msga2026-03-26CandidatePoC-in-GitHub · sylhetyhackvenger/HIKRAVENHIKRAVEN - Advanced Hikvision Security Assessment Platform for professional penetration testing. Detects 12+ CVEs including CVE-2021-36260 (CRITICAL), tests default credentials, performs network discovery, and generates professional security reports. For authorized security testing only! 🛡️🔒★ 6sylhetyhackvenger2026-07-17CandidateSource timeline
Discovered through CISA Known Exploited VulnerabilitiesView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.