A critical vulnerability in Hikvision, first disclosed in 2017, is being actively exploited by hackers to gain unauthorized access to sensitive information.
See also: Are Airbnbs safe? Check for cameras and IoT traps

SANS researchers have observed a recent increase in malicious activity targeting a specific security vulnerability, known as CVE-2017-7921 , which carries a critical severity rating of 10.0 on the CVSS scale.
Exploitation attempts are characterized by suspicious web requests to specific URLs on vulnerable cameras, such as /System/deviceInfo?auth=YWRtaW46MTEK. The base64-encoded string in the YWRtaW46MTEK decodes to admin:11. This suggests that the attackers are not using a sophisticated backdoor but are attempting to compromise devices with weak and easily predictable passwords.
The crux of the problem lies in a vulnerability in the firmware of several Hikvision camera models that allows improper authentication. This weakness allows a remote, unauthenticated attacker to bypass security measures and escalate privileges, essentially gaining control of the device. By sending a specially crafted request, an attacker can download the camera's configuration file, which may contain user credentials, or even change user passwords to lock out legitimate owners.
See also: Ring denies breach after users report strange connections

Despite Hikvision releasing firmware to address this vulnerability, hundreds of thousands of devices remain unpatched and exposed online. The problem is compounded by the fact that many other manufacturers rebrand and sell Hikvision cameras under their own names, making it difficult for users to identify whether their devices are affected.
A successful exploit can have serious consequences. Attackers can not only view live and recorded footage but also use the compromised camera as a launching point for further attacks against the internal network. The downloaded configuration files, although encrypted, use weak static-key encryption, making it possible for attackers to decrypt them and extract user credentials.
The current wave of attacks appears to be exploiting poor security practices by users. The use of a simple password like “11” may be due to the limited user interface on some Hikvision DVRs, which often only feature an on-screen numeric keypad, making it difficult to enter complex alphanumeric passwords. While placing credentials in a URL is discouraged due to the risk of them being logged, it is a convenient feature that allows for the creation of direct login links.
See also: Ring: Upgrades cameras with new AI features

To reduce the risk, Hikvision camera owners are strongly advised to update their devices’ firmware to the latest version. It is also critical to use strong, unique passwords and avoid directly exposing the camera’s management interface to the internet. If remote access is necessary, it should be done via a secure VPN connection.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
