Critical Hikvision Camera Vulnerability CVE-2021-36260 Targeted by Attackers
Key Takeaways A significant spike in scanning and remote code execution attempts against Hikvision video surveillance devices occurred in Ukraine between September 21 and October 1, 2026. The...
Key Takeaways
- A significant spike in scanning and remote code execution attempts against Hikvision video surveillance devices occurred in Ukraine between September 21 and October 1, 2026.
- The activity specifically targeted CVE-2021-36260, a critical command injection vulnerability.
- While the surge coincided with physical attacks, researchers have not confirmed a direct link between the cyber activity and Russian missile or drone strikes.
- The observed activity primarily involved exploitation attempts, not confirmed system compromises or malware installations.
- Patches are available, and immediate action is recommended for all affected Hikvision products.
Recent analysis has revealed a concentrated nine-day surge in cyberattack attempts targeting Hikvision video surveillance equipment within Ukraine. From September 21 to October 1, 2026, threat actors focused on exploiting CVE-2021-36260, a severe command injection vulnerability in unpatched devices. While this activity overlapped with Russian military actions, cybersecurity researchers have not yet established a definitive connection between the two.
Table Of Content
This renewed interest in an older flaw underscores the persistent risk posed by unpatched systems, allowing unauthorized control over vulnerable cameras and recording devices without requiring authentication. It is crucial to note, however, that the observations document attempted exploitation, not verified breaches or system takeovers, which is an important distinction when assessing the campaign’s true impact and objectives.
Hikvision Vulnerability Exploitation Surge
According to GreyNoise’s timeline, the campaign commenced with initial reconnaissance on September 21, when an IP address within a Ukrainian network initiated connections to service ports without deploying an exploit. This preliminary scanning quickly escalated into a sharp increase in exploitation attempts beginning September 23, persisting until October 1. This nine-day burst of activity followed a period of minimal comparable cyber activity directed at Ukraine.
Nearly all attempts during this surge originated from four distinct IP addresses. Three of these were identified as PureVPN exit nodes, while the fourth was traced to a domestic Ukrainian network. GreyNoise assessed with high confidence that a single entity orchestrated the VPN-based activity, though their confidence in linking the Ukrainian IP address to the same operator was lower.
The PureVPN addresses involved were 195.238.124.178, 195.238.124.181, and 195.238.124.188, all associated with AS56630 in Lithuania. It is important to consider that commercial VPN exit nodes can be utilized by various, unrelated users, so these indicators alone do not definitively prove a shared operator. The specific Ukrainian IP address was not publicly disclosed.
Despite increased global scanning for the vulnerability, GreyNoise noted that these four specific IP addresses did not attempt exploitation against their sensors outside of Ukraine. All recorded requests from this group consistently used the same command test, lacking any installation payload. No further attempts from these addresses were observed through October 7.
Understanding CVE-2021-36260
CVE-2021-36260 is a critical command injection vulnerability affecting the web server in specific Hikvision products. The flaw stems from insufficient input validation, allowing specially crafted requests containing malicious commands to be executed directly on the device’s underlying operating system. The National Institute of Standards and Technology (NIST) assigns this vulnerability a critical CVSS score of 9.8, indicating it can be exploited over a network without authentication or user interaction.
The observed activity utilized a publicly available Nuclei template titled “Hikvision IP camera/NVR – Remote Command Execution.” This suggests that the attackers were primarily engaged in automated vulnerability testing rather than immediate malware deployment or access to video feeds. GreyNoise’s observations of command-test-only requests further support this interpretation.
Historical data from 2022 revealed over 80,000 exposed and vulnerable Hikvision cameras, highlighting the long-standing exposure issue associated with this flaw. While this past count is not a current figure, it illustrates the widespread potential impact. The compromise of surveillance cameras can expose sensitive locations and activities. For instance, in January 2024, Ukrainian authorities reported neutralizing two cameras that Russian intelligence had compromised to monitor Kyiv’s air defenses and critical infrastructure. This earlier incident underscores the severe risks associated with such vulnerabilities, though it does not establish a link to the perpetrators of this latest campaign.
What You Should Do
- Immediately identify all Hikvision products within your network infrastructure.
- Apply the latest firmware updates provided by Hikvision for all affected models to patch CVE-2021-36260, as CISA recommends.
- Restrict public internet access to surveillance equipment wherever possible. Implement strong firewall rules to limit exposure.
- Isolate surveillance systems from critical network segments to prevent lateral movement in the event of a compromise.
- Regularly monitor network logs for unusual activity originating from or targeting Hikvision devices.
- Note that simply changing passwords will not remediate an unauthenticated command injection vulnerability. Firmware updates are essential.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.