Vulnerability record · CVE-2023-6895 · published 17 December 2023
CVE-2023-6895: Hikvision Intercom Broadcasting System OS command injection in ping.php
Hikvision · Intercom Broadcast System
Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK) contains an OS command injection flaw in /php/ping.php, where the jsondata[ip] argument is passed to a shell command without sanitization. A public exploit has been disclosed, and the vendor fixed the issue in version 4.1.0. Because the endpoint is network-reachable and requires no authentication, this is a high-risk pre-auth remote code execution issue for exposed deployments.
Description
A vulnerability was found in Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK). It has been declared as critical. This vulnerability affects unknown code of the file /php/ping.php. The manipulation of the argument jsondata[ip] with the input netstat -ano leads to os command injection. The exploit has been disclosed to the public and may be used. Upgrading to version 4.1.0 is able to address this issue. It is recommended to upgrade the affected component. VDB-248254 is the identifier assigned to this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityPre-auth network-reachable OS command injection with a public exploit and an EPSS score near 0.89 warrants immediate remediation.
What it is
Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK) contains an OS command injection flaw in /php/ping.php, where the jsondata[ip] argument is passed to a shell command without sanitization. A public exploit has been disclosed, and the vendor fixed the issue in version 4.1.0. Because the endpoint is network-reachable and requires no authentication, this is a high-risk pre-auth remote code execution issue for exposed deployments.
Impact
An unauthenticated attacker can execute arbitrary operating system commands on the device, leading to full compromise of confidentiality, integrity and availability. This can be used to pivot into the broader network where the intercom system is deployed.
Attack surface
Reached over the network via HTTP requests to /php/ping.php with a crafted jsondata[ip] parameter; the CVSS vector indicates no privileges or user interaction are required. Any internet- or LAN-exposed instance of the affected version is directly reachable.
Exploitation
A public exploit is referenced (GitHub willchen0011/cve rce.md tagged Exploit), and EPSS is 0.89138 (99.77th percentile), indicating very high likelihood of exploitation activity. The CVE is not listed in CISA KEV, so no confirmed in-the-wild campaign is documented in this record.
What to do
- Upgrade Hikvision Intercom Broadcasting System to version 4.1.0 or later as the vendor-recommended fix.
- If upgrade is not immediately possible, remove or block external and untrusted network access to /php/ping.php and the management interface.
- Place affected devices behind a firewall or VPN and restrict access to trusted administrative networks only.
- Monitor vendor advisories for any further patches or interim guidance for the 3.0.3 release line.
- Audit exposed instances of the product on the internet and internal networks to confirm which are still running the vulnerable version.
Detection
- Inspect web server and application logs for requests to /php/ping.php with jsondata[ip] parameters containing shell metacharacters or commands such as netstat, whoami, or curl.
- Alert on unexpected outbound network connections or process execution originating from intercom broadcasting system hosts.
- Monitor for command-injection payload patterns in HTTP query strings and POST bodies targeting the ping.php endpoint.
- Baseline normal traffic to the device management interface and flag anomalous requests from untrusted source IPs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/willchen0011/cve/blob/main/rce.md | ExploitThird Party Advisory |
| https://vuldb.com/?ctiid.248254 | Permissions RequiredThird Party Advisory |
| https://vuldb.com/?id.248254 | Third Party Advisory |
| https://github.com/willchen0011/cve/blob/main/rce.md | ExploitThird Party Advisory |
| https://vuldb.com/?ctiid.248254 | Permissions RequiredThird Party Advisory |
| https://vuldb.com/?id.248254 | Third Party Advisory |
Track CVE-2023-6895 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-6895), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.