← Vulnerability feed

Vulnerability record · CVE-2023-6895 · published 17 December 2023

CVE-2023-6895: Hikvision Intercom Broadcasting System OS command injection in ping.php

Hikvision · Intercom Broadcast System

Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK) contains an OS command injection flaw in /php/ping.php, where the jsondata[ip] argument is passed to a shell command without sanitization. A public exploit has been disclosed, and the vendor fixed the issue in version 4.1.0. Because the endpoint is network-reachable and requires no authentication, this is a high-risk pre-auth remote code execution issue for exposed deployments.

9.8 CVSS 3.1 Critical EPSS 89% · top 0.2% CWE-78 · OS command injection
9.8CVSS 3.1 base score, v2 5.8
89%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A vulnerability was found in Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK). It has been declared as critical. This vulnerability affects unknown code of the file /php/ping.php. The manipulation of the argument jsondata[ip] with the input netstat -ano leads to os command injection. The exploit has been disclosed to the public and may be used. Upgrading to version 4.1.0 is able to address this issue. It is recommended to upgrade the affected component. VDB-248254 is the identifier assigned to this vulnerability.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityPre-auth network-reachable OS command injection with a public exploit and an EPSS score near 0.89 warrants immediate remediation.

What it is

Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK) contains an OS command injection flaw in /php/ping.php, where the jsondata[ip] argument is passed to a shell command without sanitization. A public exploit has been disclosed, and the vendor fixed the issue in version 4.1.0. Because the endpoint is network-reachable and requires no authentication, this is a high-risk pre-auth remote code execution issue for exposed deployments.

Impact

An unauthenticated attacker can execute arbitrary operating system commands on the device, leading to full compromise of confidentiality, integrity and availability. This can be used to pivot into the broader network where the intercom system is deployed.

Attack surface

Reached over the network via HTTP requests to /php/ping.php with a crafted jsondata[ip] parameter; the CVSS vector indicates no privileges or user interaction are required. Any internet- or LAN-exposed instance of the affected version is directly reachable.

Exploitation

A public exploit is referenced (GitHub willchen0011/cve rce.md tagged Exploit), and EPSS is 0.89138 (99.77th percentile), indicating very high likelihood of exploitation activity. The CVE is not listed in CISA KEV, so no confirmed in-the-wild campaign is documented in this record.

What to do

  • Upgrade Hikvision Intercom Broadcasting System to version 4.1.0 or later as the vendor-recommended fix.
  • If upgrade is not immediately possible, remove or block external and untrusted network access to /php/ping.php and the management interface.
  • Place affected devices behind a firewall or VPN and restrict access to trusted administrative networks only.
  • Monitor vendor advisories for any further patches or interim guidance for the 3.0.3 release line.
  • Audit exposed instances of the product on the internet and internal networks to confirm which are still running the vulnerable version.

Detection

  • Inspect web server and application logs for requests to /php/ping.php with jsondata[ip] parameters containing shell metacharacters or commands such as netstat, whoami, or curl.
  • Alert on unexpected outbound network connections or process execution originating from intercom broadcasting system hosts.
  • Monitor for command-injection payload patterns in HTTP query strings and POST bodies targeting the ping.php endpoint.
  • Baseline normal traffic to the device management interface and flag anomalous requests from untrusted source IPs.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/willchen0011/cve/blob/main/rce.md ExploitThird Party Advisory
https://vuldb.com/?ctiid.248254 Permissions RequiredThird Party Advisory
https://vuldb.com/?id.248254 Third Party Advisory
https://github.com/willchen0011/cve/blob/main/rce.md ExploitThird Party Advisory
https://vuldb.com/?ctiid.248254 Permissions RequiredThird Party Advisory
https://vuldb.com/?id.248254 Third Party Advisory

Track CVE-2023-6895 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2023-6893Hikvision Intercom Broadcasting System path traversal in exportrecord.phpHikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK) contains a path traversal flaw in /php/exportrecord.php where the downname argumen…EPSS 70%analysed6.5CVE-2023-6894Hikvision intercom broadcast system information exposure vulnerabilityA vulnerability was found in Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK). It has been classified as problematic. This affects …EPSS 0.98%8.8CVE-2026-53266Linux kernel ebtables SNAT out-of-bounds write in ARP rewriteThe ebtables SNAT target rewrites the ARP sender hardware address via skb_store_bits() without first making that range writable. When the ARP SHA byt…KEVEPSS 0.65%analysed8.8CVE-2026-87491Google Chrome V8 out-of-bounds write enables sandbox code executionChrome before 153.0.8010.36 contains an out-of-bounds write in the V8 JavaScript engine. A crafted HTML page can trigger the memory corruption, and b…KEVEPSS 3.1%analysed9.8CVE-2025-25249Fortinet FortiOS and FortiSwitchManager heap buffer overflow via crafted packetsA heap-based buffer overflow (CWE-122/CWE-787) in Fortinet FortiOS 6.4 through 7.6.3 and FortiSwitchManager 7.0 through 7.2.6 lets an unauthenticated…KEVEPSS 3.9%analysed7.8CVE-2026-83549SonicWall SMA1000 AMC OS Command InjectionThe SMA1000 Appliance Management Console contains an OS command injection flaw (CWE-78) that lets an authenticated administrator execute arbitrary op…KEVEPSS 11%analysed10.0CVE-2026-49869Kestra OSS auth bypass via path suffix match enables RCEKestra OSS AuthenticationFilter whitelists the public config endpoint using request.getPath().endsWith("/configs"), a suffix match instead of an exac…KEVEPSS 2.1%analysed7.8CVE-2026-53362Linux kernel IPv6 UDP paged allocation out-of-bounds write__ip6_append_data() in the Linux kernel mis-accounts fraggap on the paged-allocation path, leaving the linear skb area undersized while pagedlen is o…KEVEPSS 0.71%analysed

Source: NIST National Vulnerability Database (record CVE-2023-6895), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.