Hikvision Canada Security Notification Sept 2021 Vulnerability CVE-2021-36260

Hikvision Canada Security Notification Sept 2021 Vulnerability

Hikvision has released information about a vulnerability found in many of their IP cameras, NVRs and IP camera kits.  This is a "command injection vulnerability" in the built-in web server of these products.  An attacker with access to the web interface could send malicious commands that could compromise these devices.  This has been documented with CVE ID:  CVE-2021-36260.

All Hikvision IP camera & NVR owners, users and installers are strongly suggested to check if their model is impacted and update their firmware to a patched version.  In particular, affected models that have ports forwarded from the Internet would be the most vulnerable as it exposes the device directly to remote Internet access.

For models that support P2P remote access we strongly advise against using port forwarding as a means for remote access as port forwarding directly exposes devices to the Internet.  Instead, P2P allows the NVR or camera to "push" access through a cloud service instead of exposing ports.

Please read the Hikvision security release found here:


Note:  Updating firmware incorrectly on ANY electronic device can "brick" devices rendering them inoperative.  The manufacturer may not cover this under warranty (this is their sole determination).  It's important to ensure that you completely understand and carefully follow the instructions when performing a firmware update.  That includes but is not limited to ensuring you are applying the correct firmware update, and ensuring that power is not lost to the product and it is not disconnected while in the process of updating.

Hikvision has also released a guide:  How to Upgrade Firmware
(we have also attached the guide to this article)

    • Related Articles

    • Reset Hikvision Password

      If you are the owner of a Hikvision DVR or NVR and forgot your password, you will need to have your password reset, you can use this form for Canadian customers: https://www.hikvision.com/ca-en/support/password-reset/ You will also need to have ...
    • Foscam Responds To Security Vulnerability

      Foscam hs released the following statement about a security vulnerability reported on some news channels.  Please read carefully to ensure your Foscam camera has been set up securely to prevent outside evesdropping.     Foscam thank all the people ...
    • How long is the Hikvision warranty

      > What is the warranty offered on Hikvision Nvr and cameras Hikvision offers standard 3 year warranty. Hikvision offers Gold Partners like Aartech Canada, an extra 1 year warranty for a total of 4 years.
    • How to Upgrade Hikvision Firmware

      Firmware releases may contain new features as well as security patches to fix vulnerabilities discovered over time.  It's important to keep your security cameras and NVRs up to date with current firmware to enjoy new features and keep your devices as ...
    • NDAA Compliant Security Cameras and NVRs

      NDAA as it refers to security cameras, NVRs and telecommunication equipment refers to the American National Defense Authorization Act law that was passed for the 2019 budget to block only United States federal government organizations like the ...