Uniqcli Security
← Advisories
HighHikvisionApril 2, 2024

Hikvision NVRs: Authenticated Command Injection Allows Arbitrary Command Execution

NDAA Section 889: Hikvision (Hangzhou Hikvision Digital Technology) is named in Section 889 of the FY2019 NDAA and is on the FCC Covered List. Federal agencies and federally funded programs are prohibited from procuring or using its equipment; patching does not restore eligibility, so affected NVRs must be removed and replaced with compliant hardware. This brand is a covered entity — replacing it, not just patching it, is the compliant path. See compliant replacements →

Summary

Multiple Hikvision network video recorder families contain a command injection flaw in which an account with administrative rights can break out of the intended interface and run arbitrary operating-system commands on the recorder. On a device that records and stores surveillance footage, that means an attacker who obtains or guesses admin access can pivot to full control of the appliance, tamper with evidence, and use the NVR as a beachhead into the rest of the network. The flaw spans a wide range of NI- and NXI-series recorders on firmware 5.02.005 and earlier.

Affected products

Hikvision DS-7604NI-K1/4P(B) (V4.30.096build221220 and earlier)Hikvision DS-76xxNI-Mx / DS-77xxNI-Mx / DS-96xxxNI-Mxx (V5.00.000 through V5.02.005)Hikvision DS-76xxNXI-Ix / DS-77xxNXI-Ix / DS-86xxNXI-Ix / DS-96xxNXI-Ix (V5.00.000 through V5.02.005)Hikvision iDS-76xxNXI-Mx / iDS-77xxNXI-Mx / iDS-96xxxMXI-Mxx (V5.00.000 through V5.02.005)

Impact

A user with administrative privileges can execute arbitrary commands on the underlying system (CVSS 3.1 base 7.2, vector AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H), yielding code execution, footage manipulation, persistence, and lateral movement. Because surveillance recorders are frequently deployed with default or shared credentials and exposed management interfaces, the practical attack surface is larger than the high-privilege requirement implies.

Remediation

Update affected recorders to firmware V5.02.006 or later (or the latest available build for the K-series model) and immediately remove default and shared administrator credentials. However, Hikvision is a Section 889 covered entity, so for US federal, DoD, and federally funded SLED and critical-infrastructure environments the correct remediation is removal, not patching. Uniqcli Security performs compliant rip-and-replace programs, swapping banned NVRs and cameras for TAA-compliant Axis, i-PRO, Hanwha, or Bosch recording infrastructure on Milestone or Genetec, with documentation for your audit file.

Sources

Want us to handle it?

We patch, harden or replace affected devices and document the closeout.

Request a fleet scan
Stay ahead of it

Scan your fleet for vulnerable or banned devices.

Tell us what you need secured. We'll confirm compliance, design the system, and quote it — no payment up front.

Hikvision NVRs: Authenticated Command Injection Allows Arbitrary Command Execution | Uniqcli Security Advisories