Vulnerability record · CVE-2014-4880 · published 8 December 2014
CVE-2014-4880: Hikvision DVR RTSP Authorization header buffer overflow
Hikvision · Dvr Ds 7204 Firmware
Hikvision DVR firmware (DS-7204 2.2.10 build 131009 and other models/versions) contains a buffer overflow reachable through an RTSP PLAY request carrying an overly long Authorization header. Successful exploitation allows remote code execution on the device. Because these are network-facing surveillance appliances, the flaw matters for any deployment exposing RTSP.
Description
Buffer overflow in Hikvision DVR DS-7204 Firmware 2.2.10 build 131009, and other models and versions, allows remote attackers to execute arbitrary code via an RTSP PLAY request with a long Authorization header.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityUnauthenticated remote code execution with public exploit code and very high EPSS, though not currently in CISA KEV.
What it is
Hikvision DVR firmware (DS-7204 2.2.10 build 131009 and other models/versions) contains a buffer overflow reachable through an RTSP PLAY request carrying an overly long Authorization header. Successful exploitation allows remote code execution on the device. Because these are network-facing surveillance appliances, the flaw matters for any deployment exposing RTSP.
Impact
An unauthenticated remote attacker can execute arbitrary code on the DVR, gaining control of the device and potentially the video data and network segment it sits on.
Attack surface
Reached over the network via the RTSP service; the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required, only network access to the RTSP port.
Exploitation
Public exploit code exists (Packet Storm and Exploit-DB references tagged Exploit), and EPSS is high at roughly 0.71 (99th percentile), though the CVE is not listed in CISA KEV.
What to do
- Apply the vendor firmware update for the affected DVR models; if no fixed firmware exists for a given model, replace or retire the device.
- Remove direct internet exposure of DVR RTSP and management interfaces; place them behind a firewall or VPN with strict allowlists.
- Disable or restrict RTSP where it is not required, and change default credentials on any remaining management access.
- Segment cameras and DVRs onto an isolated VLAN so a compromised device cannot reach other internal systems.
Detection
- Monitor RTSP traffic for abnormally long Authorization headers or malformed PLAY requests targeting DVR endpoints.
- Alert on crashes, restarts or unexpected process behavior on DVR devices, which can indicate a failed overflow attempt.
- Watch for outbound connections from DVR/camera VLANs to unfamiliar hosts, a common sign of post-exploitation activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2014-4880 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-4880), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.