HomeSecurityOver 80,000 Hikvision cameras vulnerable to critical vulnerability

Over 80,000 Hikvision cameras vulnerable to critical vulnerability

Security researchers have discovered over 80,000 Hikvision cameras vulnerable to a critical command injection vulnerability. According to the researchers, an attacker could easily exploit this vulnerability via specially crafted messages sent to the vulnerable web server.

Hikvision cameras vulnerability

The flaw is tracked as CVE-2021-36260 and Hikvision fixed it via a firmware update released in September 2021.

See also: Hackers steal crypto due to zero-day vulnerability in Bitcoin ATM

However, according to a new report published by CYFIRMA, tens of thousands of systems used by at least 2,300 organizations in 100 countries have yet to apply the security update, meaning the cameras remain vulnerable.

There have been two known public exploits for the CVE-2021-36260 vulnerability in Hikvision cameras: one published in October 2021 and the second in February 2022.Therefore, cybercriminals (whether with a lot of knowledge or not) can seek out and exploit vulnerable cameras.

In December 2021, a Mirai-based botnet called “Moobot” used an exploit to spread aggressively and recruit systems for DdoS attacks.

In January 2022, CISA included CVE-2021-36260 on its list of bugs actively used in attacks, warning organizations that attackers could “take control” of devices.

See also: WordPress: Fake Cloudflare notifications are distributing malware

CYFIRMA researchers now say that Russian-language hacking forums often sell network entry points based on “exploitable” Hikvision cameras that can be used for either “botnetting” or lateral movement.

From a sample of 285,000 Hikvision web servers that have access to the Internet, the cybersecurity company found about 80,000 cameras that are still vulnerable.

Most of these are located in China and the United States, while the United Kingdom, Ukraine, France, the Netherlands, Romania, Vietnam, Thailand, and South Africa count over 2,000 vulnerable endpoints.

The exploit of the flaw does not follow a specific pattern, as it is exploited by many different groups. However, CYFIRMA highlights the cases of Chinese hacking groups APT41 and APT10, as well as Russian groups specializing in cyberespionage.

See also: Hackers target hotels and infect systems with malware

Weak passwords: Another big problem

In addition to the vulnerability affecting Hikvision cameras, there is also the issue of weak passwords. Many users choose simple passwords for convenience or do not change the passwords that come with the device by default.

According to Bleeping Computer, there are many lists (some even free) on hacking forums that contain credentials for live video feeds from Hikvision cameras.

If you are using a Hikvision camera, you should immediately install the latest available firmware update, use a strong password , and isolate your IoT network from critical components using a firewall or VLAN.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS