Tens of Thousands of Hikvision Cameras Remain Critically Vulnerable to 11-Month-Old Exploit, Exposing Organizations Globally

An alarming security lapse continues to leave tens of thousands of organizations worldwide exposed, as a critical command injection vulnerability in Hikvision surveillance cameras, first disclosed nearly a year ago, remains unpatched in an estimated 80,000 devices. This persistent oversight, detailed in recent research, highlights a significant chasm in IoT security practices and raises serious concerns about the potential for widespread cyber espionage and disruption.
The vulnerability, identified by the Common Vulnerabilities and Exposures (CVE) system as CVE-2021-36260, was assigned a severe "critical" rating of 9.8 out of 10 by the National Institute of Standards and Technology (NIST). This designation underscores the ease with which attackers can exploit the flaw to gain unauthorized access and execute arbitrary commands on affected camera systems. Despite the gravity of the situation and the ample time for remediation, a substantial number of Hikvision devices continue to operate with this dangerous backdoor.
Hikvision, officially Hangzhou Hikvision Digital Technology, is a major Chinese state-owned manufacturer of video surveillance equipment. Its products are deployed in over 100 countries, including the United States. However, the company has faced scrutiny regarding its national security implications. In 2019, the U.S. Federal Communications Commission (FCC) designated Hikvision as an "unacceptable risk to U.S. national security," a warning that appears to have been largely unheeded by many entities continuing to utilize the company’s equipment without adequate security measures.
A Timeline of Neglect and Growing Threats
The story of CVE-2021-36260 began to unfold in the latter half of last year. The command injection flaw, which allows an attacker to inject malicious commands into a system through specially crafted input, was publicly revealed. Security researchers and cybersecurity agencies immediately flagged the severity of this vulnerability, urging users to apply available patches.
However, the adoption of these critical updates has been demonstrably slow. The recent research indicates that even after nearly a year, the majority of affected Hikvision cameras remain susceptible. This prolonged period of exposure has not gone unnoticed by malicious actors. Investigators have observed multiple instances on Russian dark web forums where individuals are actively seeking collaborators to exploit this specific Hikvision vulnerability. Furthermore, the sale of leaked credentials, likely obtained from compromised Hikvision devices, has been reported, indicating an active marketplace for exploiting these unsecured systems.
The full extent of the damage already inflicted by this vulnerability remains largely unknown. The authors of the research report have offered cautious speculation regarding the potential perpetrators and their motives. They suggest that Chinese state-sponsored threat groups, such as MISSION2025/APT41 and APT10, along with their affiliates, could leverage these compromised devices. Additionally, unidentified Russian threat actor groups are also considered potential exploiters. The motivations behind such attacks could range from intelligence gathering and corporate espionage to broader geo-political objectives, given the widespread deployment of Hikvision cameras in sensitive locations.
The Pervasive Risks Within the Internet of Things (IoT) Ecosystem
The persistent vulnerability of Hikvision cameras serves as a stark illustration of broader challenges within the Internet of Things (IoT) security landscape. While it might be tempting to attribute the issue solely to user negligence or "laziness," the reality is often more complex and systemic.
David Maynor, Senior Director of Threat Intelligence at Cybrary, points to a confluence of factors contributing to the prolonged vulnerability of Hikvision products. "Their product contains easy-to-exploit systemic vulnerabilities or worse, uses default credentials," Maynor stated. He further elaborated on the difficulties in remediation, noting, "There is no good way to perform forensics or verify that an attacker has been excised. Furthermore, we have not observed any change in Hikvision’s posture to signal an increase in security within their development cycle." This suggests a potential lack of proactive security integration into Hikvision’s product development and lifecycle management.
Paul Bischoff, a privacy advocate with Comparitech, echoed these sentiments, emphasizing the inherent difficulties in securing IoT devices compared to more conventional computing systems. "IoT devices like cameras aren’t always as easy or straightforward to secure as an app on your phone," Bischoff explained in an email statement. "Updates are not automatic; users need to manually download and install them, and many users might never get the message. Furthermore, IoT devices might not give users any indication that they’re unsecured or out of date. Whereas your phone will alert you when an update is available and likely install it automatically the next time you reboot, IoT devices do not offer such conveniences."
This lack of automatic updates and user-friendly notification mechanisms creates a significant blind spot for many users. In the absence of explicit alerts, devices can languish with outdated firmware, unaware of the ticking time bomb within their networks.
Compounding these issues is the prevalence of weak default security settings. As Bischoff highlighted, "Hikvision cameras come with one of a few predetermined passwords out of the box, and many users don’t change these default passwords." This practice, unfortunately common across various IoT device manufacturers, provides attackers with an immediate and low-effort entry point. Cybercriminals can readily scan the internet for vulnerable devices using specialized search engines like Shodan and Censys, identifying and exploiting these systems with alarming ease.
The combination of inherent design weaknesses, a lack of user awareness regarding update procedures, and the continued reliance on default credentials creates a perfect storm for cyber threats. With tens of thousands of these cameras potentially compromised, the risk of widespread surveillance, data breaches, and network infiltration is substantial and ongoing. The question of when, or even if, these tens of thousands of devices will be adequately secured remains a critical concern for cybersecurity professionals and the organizations that rely on them.
Implications for Global Cybersecurity and National Security
The persistent vulnerability of Hikvision cameras has far-reaching implications that extend beyond individual organizations. The sheer scale of the unpatched devices, coupled with the critical nature of the flaw, presents a significant vector for state-sponsored espionage and cyber warfare.
Intelligence Gathering: Compromised cameras can be used to conduct persistent surveillance, providing adversaries with real-time visual intelligence on sensitive locations, critical infrastructure, government facilities, and private enterprises. This intelligence can inform strategic planning, target selection for future attacks, and provide insights into operational security.
Network Infiltration and Lateral Movement: Once a camera is compromised, it can serve as an initial foothold within a network. Attackers can then leverage this access to pivot to other, more valuable systems, escalating their intrusion to steal sensitive data, disrupt operations, or deploy ransomware. The ability to inject arbitrary commands means attackers could potentially use these devices to launch further attacks against other targets on the same network.
Disruption of Critical Infrastructure: In regions where Hikvision cameras are integrated into security systems for power grids, transportation networks, or other critical infrastructure, a widespread compromise could lead to significant operational disruptions, posing a threat to public safety and economic stability.
Erosion of Trust in IoT Security: Incidents like this erode public and organizational trust in the security of IoT devices. As more devices become connected, the attack surface for cybercriminals and hostile actors expands exponentially. The failure to adequately address known vulnerabilities in widely deployed devices like Hikvision cameras sends a concerning message about the commitment of some manufacturers to user security.
Geopolitical Ramifications: Given Hikvision’s state-owned status and the involvement of state-sponsored threat actors, this vulnerability also carries significant geopolitical weight. It underscores the ongoing cyber arms race and the potential for technology to be weaponized for national interests, even when deployed in civilian sectors. The FCC’s 2019 designation highlights the existing concerns within the U.S. government regarding the security risks posed by Chinese-manufactured telecommunications and surveillance equipment.
Recommendations and Future Outlook
Addressing this ongoing crisis requires a multi-pronged approach.
- For Organizations: Immediate action is paramount. Organizations using Hikvision cameras must prioritize patching their devices. If patching is not feasible or immediate updates are unavailable, implementing network segmentation to isolate these devices, disabling remote access, and enhancing monitoring for suspicious activity are crucial mitigation steps. A comprehensive audit of all IoT devices within an organization’s network is also highly recommended.
- For Hikvision: The company faces increased pressure to provide prompt and effective security updates, transparently communicate risks to its customers, and fundamentally reassess its product development lifecycle to incorporate robust security-by-design principles. Investing in proactive security research and a more responsive vulnerability management program is essential to regain customer trust.
- For Regulators and Policymakers: This incident reinforces the need for stronger regulatory frameworks governing IoT device security. Mandating secure-by-default configurations, requiring manufacturers to provide long-term support and timely updates, and establishing clear liability for security failures could incentivize better practices across the industry. Governments may also need to consider stricter import controls and security audits for critical technology from nations with known cyber espionage concerns.
- For the Cybersecurity Community: Continued vigilance, threat intelligence sharing, and the development of advanced detection and response capabilities are vital. Public awareness campaigns about IoT security risks and best practices are also essential to empower users to protect themselves.
The lingering threat posed by CVE-2021-36260 in Hikvision cameras serves as a critical reminder that in the interconnected digital age, cybersecurity is not merely an IT concern but a fundamental aspect of organizational resilience and national security. The failure to address such critical vulnerabilities promptly leaves the door open for significant and potentially devastating cyber incursions.






