Tens of Thousands of Hikvision Surveillance Cameras Remain Vulnerable to Critical Unpatched Command Injection Flaw Nearly a Year Later

More than 80,000 Hikvision surveillance cameras deployed globally remain exposed to a severe, eleven-month-old cybersecurity vulnerability that could allow malicious actors to execute arbitrary commands remotely. Despite a critical severity rating issued by federal authorities and repeated warnings from threat intelligence researchers, thousands of organizations across over one hundred countries continue to operate these unpatched devices, creating an expansive attack surface for both state-sponsored advanced persistent threat (APT) groups and opportunistic cybercriminals.
The vulnerability, formally designated as CVE-2021-36260, is a command injection flaw residing in the web server of numerous Hikvision IP camera models. Disclosed publicly in the autumn of 2021, the vulnerability received a maximum severity score of 9.8 out of 10 on the Common Vulnerability Scoring System (CVSS) managed by the National Institute of Standards and Technology (NIST). The flaw stems from improper input validation in the web management interface, which allows an unauthenticated, network-adjacent attacker to craft malicious messages and execute arbitrary commands on the underlying operating system of the affected hardware.
The manufacturer at the center of the controversy is Hangzhou Hikvision Digital Technology Co., Ltd., a partially state-owned video surveillance manufacturer headquartered in Zhejiang, China. Hikvision products are ubiquitous in both the private and public sectors globally, securing commercial properties, critical infrastructure, educational institutions, and residential areas. However, the company’s hardware has faced mounting scrutiny from international regulators and cybersecurity agencies over the past several years. In 2019, the United States Federal Communications Commission (FCC) designated Hikvision as an unacceptable risk to U.S. national security, citing concerns over foreign intelligence gathering and data privacy, though millions of units remain operational in Western markets.
Chronology of an Overlooked Flaw
The lifecycle of CVE-2021-36260 highlights the persistent challenges surrounding vulnerability disclosure and remediation within the Internet of Things (IoT) ecosystem.
In September 2021, cybersecurity researchers identified the remote code execution vulnerability in a wide range of Hikvision IP cameras and video management systems. Following standard responsible disclosure practices, the findings were communicated to the vendor, prompting Hikvision to release an official security advisory and firmware updates designed to mitigate the flaw. However, despite the vendor’s patch availability, the rate of adoption among end-users and enterprise system administrators has lagged significantly.
By early 2022, approximately six months after the initial patch release, telemetry data indicated that tens of thousands of devices had still not been updated. Security analysts noted that threat actors began actively scanning the public internet for vulnerable endpoints using specialized search engines such as Shodan and Censys.
As the vulnerability approached its one-year anniversary, fresh intelligence reports published by security firms revealed that malicious actors had begun discussing and collaborating on exploitation methods within underground forums, specifically targeting Russian-language dark web communities. Furthermore, threat actors began aggregating and monetizing unauthorized access to vulnerable systems, offering harvested credentials and reverse-shell access to the highest bidder.
Data and Scale of Exposure
Recent telemetry and threat intelligence assessments indicate that approximately 80,000 Hikvision cameras remain actively vulnerable to CVE-2021-36260 worldwide. Because these devices are frequently connected directly to the internet to allow remote monitoring via mobile applications and web browsers, they can be discovered by automated scripts within seconds.
The geographic distribution of these exposed devices spans more than 100 countries, including the United States, various European Union member states, South America, and parts of Asia. While enterprise-level organizations often maintain centralized IT departments capable of deploying firmware updates across thousands of endpoints simultaneously, smaller businesses, residential users, and organizations with decentralized security management structures frequently lack the visibility required to identify outdated hardware.
Security researchers have expressed particular concern over the intersection of unpatched firmware and weak default configurations. Many Hikvision devices are deployed with factory-default administrative credentials or easily guessable passwords. When combined with an unauthenticated command injection vulnerability, attackers do not even need to perform brute-force attacks to gain full administrative control over the camera; a single crafted HTTP request is sufficient to compromise the device entirely.
Threat Actor Interest and Geopolitical Implications
The persistence of unpatched Hikvision infrastructure has naturally attracted the attention of sophisticated threat actors. While low-tier cybercriminals typically leverage compromised IoT devices to build botnets for distributed denial-of-service (DDoS) attacks or cryptocurrency mining operations, state-sponsored actors view these devices through a strategic lens.
Cybersecurity researchers have highlighted that advanced persistent threat groups could exploit these vulnerabilities to establish long-term footholds inside corporate or governmental networks. Because IP cameras are often installed on the perimeter of an organization’s network—frequently trusted implicitly by internal firewalls—a compromised camera can serve as a convenient pivot point for lateral movement into deeper, more sensitive segments of an enterprise network.
Although definitive attribution of ongoing attacks remains difficult due to the obfuscated nature of network intrusions, threat intelligence analysts have speculated that various state-backed cyber espionage units could leverage these flaws. Groups linked to intelligence-gathering operations, including those tracked under designations such as APT10, MISSION2025 (APT41), and associated regional collectives, frequently scan for perimeter vulnerabilities to conduct reconnaissance and supply-chain espionage. The geopolitical tensions between Western nations and the country of origin for the device manufacturer further elevate the strategic risk profile of these compromised assets.
Structural Challenges in Securing the IoT Ecosystem
The failure to patch CVE-2021-36260 nearly a year after its discovery is not an isolated incident, but rather a symptom of broader, systemic vulnerabilities within the Internet of Things manufacturing and deployment lifecycle. Industry experts emphasize that securing IoT devices presents fundamental challenges that differ vastly from traditional computing environments.
David Maynor, senior director of threat intelligence at Cybrary, points out that the architectural design of many commercial surveillance products often impedes robust security postures. According to Maynor, some manufacturer product lines suffer from systemic vulnerabilities embedded deeply within their firmware architectures, coupled with a historical reliance on predictable default credentials. Furthermore, Maynor notes that device forensics remain notoriously difficult; if an attacker compromises a standard IP camera, there is often no reliable logging mechanism or forensic tool available to system administrators to verify whether the intrusion occurred or to ensure that the malicious payload has been completely excised. Additionally, critics argue that the manufacturer’s internal software development lifecycle and update distribution models have historically lacked the transparency and urgency required to meet modern enterprise security standards.
The user experience barrier also plays a critical role in delayed remediation. Paul Bischoff, a privacy advocate and security researcher with Comparitech, highlights the inherent friction in IoT maintenance compared to consumer electronics or desktop software.
"IoT devices like cameras aren’t always as easy or straightforward to secure as an app on your phone," Bischoff explained. "Updates are not automatic; users need to manually download and install them, and many users might never get the message. Furthermore, IoT devices might not give users any indication that they’re unsecured or out of date. Whereas your phone will alert you when an update is available and likely install it automatically the next time you reboot, IoT devices do not offer such conveniences."
This absence of automated over-the-air update mechanisms means that security maintenance is entirely dependent on human intervention. For thousands of small business owners and residential consumers who view security cameras as "set-and-forget" appliances, checking for firmware updates is rarely a routine maintenance task.
Compounding the issue is the widespread failure to alter factory settings during initial installation. Despite recurring warnings from cybersecurity agencies regarding the dangers of default passwords, a significant percentage of deployed cameras operate using the exact credentials printed on the packaging or detailed in the quick-start guide. When device owners neglect to modify these credentials or segment their IoT hardware onto isolated Virtual Local Area Networks (VLANs), the impact of a single unpatched vulnerability is magnified exponentially.
Broader Impact and Industry Implications
The ongoing exposure of tens of thousands of Hikvision cameras underscores a critical vulnerability in the global digital supply chain. As physical security systems become increasingly digitized and integrated into IP networks—a trend commonly referred to as the convergence of physical and logical security—the boundary between IT infrastructure and operational technology (OT) continues to blur.
A breach originating from an unpatched surveillance camera can have cascading consequences for an organization. Beyond the obvious privacy violations associated with unauthorized video stream access, attackers who establish a foothold via IoT devices can capture sensitive internal network traffic, intercept credentials, launch internal network reconnaissance, or disrupt physical security operations by disabling recording capabilities or manipulating camera feeds during physical break-ins.
Regulatory bodies and industry standards organizations are increasingly examining the accountability of IoT manufacturers. Calls for mandatory software bills of materials (SBOMs), stricter baseline cybersecurity standards for imported hardware, and legally enforced vulnerability disclosure timelines are gaining traction in several jurisdictions. However, regulatory frameworks take years to formalize and implement, leaving the immediate burden of defense on enterprise network administrators and end-users.
Recommendations for Mitigation
Cybersecurity agencies, including the Cybersecurity and Infrastructure Security Agency (CISA) and international counterparts, strongly advise organizations utilizing Hikvision equipment to take immediate remediation steps.
First and foremost, network administrators must apply the latest firmware updates provided by the manufacturer for CVE-2021-36260. Organizations should verify their asset inventories to identify all deployed surveillance devices, ensuring that no legacy or forgotten units remain operational without current patches.
Second, organizations must enforce strict credential management protocols. All default usernames and passwords must be changed immediately upon installation, and weak or shared passwords should be replaced with complex, unique passphrases managed through secure enterprise password vaults.
Finally, network segmentation should be implemented as a mandatory defense-in-depth measure. IP cameras and other IoT hardware ought to be isolated on dedicated VLANs with strict firewall rules preventing direct exposure to the public internet. Access to camera management interfaces should be restricted strictly to internal management networks, preferably mediated through secure Virtual Private Networks (VPNs) with multi-factor authentication enforced for all administrative sessions.
Until device manufacturers adopt automated update paradigms and users prioritize proactive security hygiene, the risk posed by unpatched IoT infrastructure will remain a persistent vulnerability in the global cybersecurity landscape.






