Vulnerability record · CVE-2017-7921 · published 6 May 2017
CVE-2017-7921: Hikvision IP cameras improper authentication allows privilege escalation
Hikvision · Ds 2cd2032 I Firmware
Hikvision IP camera firmware fails to properly authenticate users, letting an unauthenticated remote attacker escalate privileges and reach sensitive data. The flaw spans many DS-2CD and DS-2DF camera series and firmware builds. Because the devices are network-exposed and the issue is trivially reachable, it is a serious exposure for camera fleets.
Description
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I Series V5.2.0 build 140721 to V5.4.0 Build 160401, DS-2CD2xx2FWD Series V5.3.1 build 150410 to V5.4.4 Build 161125, DS-2CD4x2xFWD Series V5.2.0 build 140721 to V5.4.0 Build 160414, DS-2CD4xx5 Series V5.2.0 build 140721 to V5.4.0 Build 160421, DS-2DFx Series V5.2.0 build 140805 to V5.4.5 Build 160928, and DS-2CD63xx Series V5.0.9 build 140305 to V5.3.5 Build 160106 devices. The improper authentication vulnerability occurs when an application does not adequately or correctly authenticate users. This may allow a malicious user to escalate his or her privileges on the system and gain access to sensitive information.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, KEV-listed, and near-certain EPSS probability make this an actively exploited, remotely reachable authentication bypass.
What it is
Hikvision IP camera firmware fails to properly authenticate users, letting an unauthenticated remote attacker escalate privileges and reach sensitive data. The flaw spans many DS-2CD and DS-2DF camera series and firmware builds. Because the devices are network-exposed and the issue is trivially reachable, it is a serious exposure for camera fleets.
Impact
An attacker gains elevated access on the camera and can read sensitive information, including configuration and credentials, and potentially take full control of the device.
Attack surface
Reachable over the network via HTTP on affected camera firmware with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N.
Exploitation
Listed in CISA KEV with a 30-day EPSS probability near 1.0, indicating active exploitation in the wild; no ransomware campaign use is documented.
What to do
- Apply the vendor patch or firmware update for the affected Hikvision camera models and builds.
- If patching is not possible, isolate cameras on a segmented VLAN with no internet exposure and restrict management access.
- Disable or block remote access to camera web interfaces from untrusted networks.
- Replace end-of-support devices that cannot be updated.
- Follow CISA BOD 22-01 guidance or discontinue use where mitigations are unavailable.
Detection
- Monitor camera web logs for unauthenticated requests to privileged endpoints or configuration paths.
- Alert on unexpected outbound traffic or new admin sessions from camera devices.
- Scan the network for affected Hikvision firmware versions and flag unpatched devices.
- Watch for authentication bypass patterns or anomalous access to sensitive camera endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2017-7921 to the Known Exploited Vulnerabilities catalog on 5 March 2026 as "Hikvision Multiple Products Improper Authentication Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 26 March 2026.
Affected products
58 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2017-7921 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-7921), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.