← Vulnerability feed

Vulnerability record · CVE-2017-7921 · published 6 May 2017

CVE-2017-7921: Hikvision IP cameras improper authentication allows privilege escalation

Hikvision · Ds 2cd2032 I Firmware

Hikvision IP camera firmware fails to properly authenticate users, letting an unauthenticated remote attacker escalate privileges and reach sensitive data. The flaw spans many DS-2CD and DS-2DF camera series and firmware builds. Because the devices are network-exposed and the issue is trivially reachable, it is a serious exposure for camera fleets.

9.8 CVSS 3.1 Critical CISA KEV since 5 Mar 2026 EPSS 100% · top 0.1% CWE-287 · Improper authentication
9.8CVSS 3.1 base score, v2 7.5
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
58Affected product versions listed by NVD
12References
17 Jun 2026Last modified by NVD

Description

An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I Series V5.2.0 build 140721 to V5.4.0 Build 160401, DS-2CD2xx2FWD Series V5.3.1 build 150410 to V5.4.4 Build 161125, DS-2CD4x2xFWD Series V5.2.0 build 140721 to V5.4.0 Build 160414, DS-2CD4xx5 Series V5.2.0 build 140721 to V5.4.0 Build 160421, DS-2DFx Series V5.2.0 build 140805 to V5.4.5 Build 160928, and DS-2CD63xx Series V5.0.9 build 140305 to V5.3.5 Build 160106 devices. The improper authentication vulnerability occurs when an application does not adequately or correctly authenticate users. This may allow a malicious user to escalate his or her privileges on the system and gain access to sensitive information.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 9.8, KEV-listed, and near-certain EPSS probability make this an actively exploited, remotely reachable authentication bypass.

What it is

Hikvision IP camera firmware fails to properly authenticate users, letting an unauthenticated remote attacker escalate privileges and reach sensitive data. The flaw spans many DS-2CD and DS-2DF camera series and firmware builds. Because the devices are network-exposed and the issue is trivially reachable, it is a serious exposure for camera fleets.

Impact

An attacker gains elevated access on the camera and can read sensitive information, including configuration and credentials, and potentially take full control of the device.

Attack surface

Reachable over the network via HTTP on affected camera firmware with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N.

Exploitation

Listed in CISA KEV with a 30-day EPSS probability near 1.0, indicating active exploitation in the wild; no ransomware campaign use is documented.

What to do

  • Apply the vendor patch or firmware update for the affected Hikvision camera models and builds.
  • If patching is not possible, isolate cameras on a segmented VLAN with no internet exposure and restrict management access.
  • Disable or block remote access to camera web interfaces from untrusted networks.
  • Replace end-of-support devices that cannot be updated.
  • Follow CISA BOD 22-01 guidance or discontinue use where mitigations are unavailable.

Detection

  • Monitor camera web logs for unauthenticated requests to privileged endpoints or configuration paths.
  • Alert on unexpected outbound traffic or new admin sessions from camera devices.
  • Scan the network for affected Hikvision firmware versions and flag unpatched devices.
  • Watch for authentication bypass patterns or anomalous access to sensitive camera endpoints.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2017-7921 to the Known Exploited Vulnerabilities catalog on 5 March 2026 as "Hikvision Multiple Products Improper Authentication Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 26 March 2026.

Affected products

58 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-7921 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2017-7923Hikvision ds-2cd2032-i firmware information exposure vulnerabilityA Password in Configuration File issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I Ser…EPSS 2.4%7.5CVE-2026-42018JFrog Artifactory improper authentication leaks anonymous tokenJFrog Artifactory can return an internal anonymous-user token to an unauthenticated caller even when anonymous access is disabled. Because the token …KEVEPSS 9.8%analysed9.8CVE-2026-82329JFrog Artifactory improper authentication allows admin takeoverJFrog Artifactory contains an improper authentication weakness (CWE-287) that, under default configuration, may let an unauthenticated attacker with …KEVEPSS 14%analysed8.8CVE-2026-59822LiteLLM MCP endpoint auth bypass via OAuth2 passthrough fallbackLiteLLM's MCP Streamable HTTP endpoint, prior to 1.84.0, let an unauthenticated attacker send a fabricated Authorization header that triggered an OAu…KEVEPSS 0.84%analysed10.0CVE-2026-49869Kestra OSS auth bypass via path suffix match enables RCEKestra OSS AuthenticationFilter whitelists the public config endpoint using request.getPath().endsWith("/configs"), a suffix match instead of an exac…KEVEPSS 2.1%analysed9.8CVE-2023-49105ownCloud Server WebDAV authentication bypass via pre-signed URLsownCloud core before 10.13.1 accepts pre-signed URLs even when the file owner has no signing-key configured, so the signature check is effectively sk…KEVEPSS 43%analysed9.8CVE-2026-65400Apple macOS Screen Sharing authentication bypassAn improper authentication flaw in Apple macOS Screen Sharing allows a network attacker to authenticate without valid credentials. Apple fixed it via…KEVEPSS 1.2%analysed9.3CVE-2026-16232Check Point SmartConsole authentication bypass grants admin tokenCheck Point SmartConsole login contains an improper authentication flaw (CWE-287) that lets an unauthenticated remote attacker obtain an application …KEVEPSS 78%analysed

Source: NIST National Vulnerability Database (record CVE-2017-7921), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.