Critical Hikvision Vulnerability Persists: Tens of Thousands of Surveillance Cameras Globally Remain Unpatched, Posing Significant Cybersecurity Risks

Over 80,000 Hikvision surveillance cameras worldwide are currently vulnerable to a critical command injection flaw, CVE-2021-36260, nearly a year after its initial public disclosure. This widespread exposure leaves a vast array of organizations and potentially critical infrastructure susceptible to exploitation by malicious actors, raising alarms across the cybersecurity landscape and highlighting persistent challenges in the management of Internet of Things (IoT) device security. New research from Cyfirma, published in August 2022, brought this alarming statistic to light, underscoring a significant lapse in patch management and user awareness despite the severity of the vulnerability.
The persistent vulnerability affects devices manufactured by Hangzhou Hikvision Digital Technology, a Chinese state-owned enterprise that stands as one of the world’s largest suppliers of video surveillance equipment. With a global customer base spanning over 100 countries, including a notable presence in the United States, the scale of this unpatched flaw presents a formidable national security and privacy concern. This is particularly salient given the U.S. Federal Communications Commission (FCC) designated Hikvision as "an unacceptable risk to U.S. national security" in 2019, a classification that has since led to further restrictions on the company’s equipment in the U.S. market.
The Anatomy of a Critical Flaw: CVE-2021-36260
The command injection flaw, identified as CVE-2021-36260, first came to public attention in the fall of 2021. The National Institute of Standards and Technology (NIST) assigned it a "critical" severity rating of 9.8 out of 10 on its Common Vulnerability Scoring System (CVSS) scale, signifying the highest possible risk level. A command injection vulnerability allows an attacker to execute arbitrary commands on a host operating system via a vulnerable application. In the context of networked cameras, this means an unauthorized individual could potentially gain full control over the device, access its video feed, manipulate its functions, or even use it as a pivot point to infiltrate deeper into an organization’s network.
Such a high-severity flaw typically necessitates immediate and widespread patching. However, the Cyfirma report reveals a stark reality: almost a year after the vulnerability was first disclosed and patches presumably made available by Hikvision, over 80,000 devices remain exposed. The failure to patch these devices creates an enormous attack surface that sophisticated threat actors are actively seeking to exploit. Cyfirma’s researchers have observed "multiple instances of hackers looking to collaborate on exploiting Hikvision cameras using the command injection vulnerability," with particular activity noted in Russian dark web forums where stolen credentials for these devices have been openly advertised for sale. This indicates a clear and present danger, transitioning from theoretical vulnerability to active exploitation attempts.
Chronology of Exposure and Escalating Risk
The timeline of CVE-2021-36260 illustrates a protracted period of vulnerability that highlights systemic issues in IoT security:
- Fall 2021: The command injection vulnerability (CVE-2021-36260) in Hikvision surveillance cameras is publicly disclosed. Details become available through security advisories and databases like NIST’s NVD. Hikvision is expected to have released firmware updates to address the flaw.
- Late 2021 – Early 2022: Initial attempts at exploitation are observed by cybersecurity researchers. The critical nature of the flaw means that threat actors would quickly reverse-engineer patches to develop exploits.
- August 2022: Cyfirma’s comprehensive research is published, revealing that despite the nearly year-long window for patching, over 80,000 Hikvision cameras remain unpatched. This research quantifies the persistent threat and identifies active discussions and collaboration among cybercriminals on dark web platforms, specifically in Russian forums, targeting these vulnerable devices. The report also notes the sale of leaked credentials for Hikvision cameras, further lowering the barrier to entry for potential attackers.
- Ongoing: The risk continues to compound as more time passes without widespread patching. Each day that passes increases the likelihood of successful exploitation, potentially leading to data breaches, espionage, or even physical security compromises.
The true extent of the damage already inflicted due to this unpatched vulnerability remains largely unclear. The authors of the Cyfirma report could only speculate on the potential involvement of state-sponsored groups, stating, "Chinese threat groups such as MISSION2025/APT41, APT10 and its affiliates, as well as unknown Russian threat actor groups could potentially exploit vulnerabilities in these devices to fulfill their motives (which may include specific geo-political considerations)." This highlights the strategic significance of surveillance equipment as potential vectors for state-sponsored cyber espionage and sabotage.
Hikvision’s Controversial Global Footprint
Hikvision’s market dominance and its ties to the Chinese government have long been a source of geopolitical tension and security concerns. Founded in 2001, the company rapidly ascended to become the world’s largest supplier of video surveillance products, leveraging extensive government subsidies and a robust research and development arm. Its cameras and recording devices are ubiquitous, deployed in various settings ranging from public infrastructure, government buildings, and corporate campuses to small businesses and private residences.
The U.S. government, among others, has voiced increasing concern over the security implications of using equipment from companies with close ties to foreign adversaries. In 2019, the FCC’s "unacceptable risk" designation for Hikvision was based on the premise that its equipment could be used for espionage by the Chinese government. This concern intensified with the passage of the Secure Equipment Act of 2021, which effectively barred the FCC from reviewing or approving new equipment authorizations for companies like Hikvision that are deemed national security threats. These actions underscore the broader geopolitical context surrounding the use of Chinese-made technology in critical infrastructure and sensitive environments, where potential backdoors or vulnerabilities could be leveraged for intelligence gathering or disruption.
Beyond national security concerns, Hikvision has also faced scrutiny regarding its alleged involvement in human rights abuses, specifically its role in supplying surveillance equipment used in Xinjiang for monitoring the Uyghur minority population. While not directly related to CVE-2021-36260, these broader ethical and political controversies contribute to the heightened scrutiny and inherent mistrust surrounding the company’s products and their potential vulnerabilities.
The Broader Challenge of IoT Device Security
While it might be tempting to attribute the widespread failure to patch solely to organizational laziness, the reality of IoT device security is far more complex. As David Maynor, Senior Director of Threat Intelligence at Cybrary, points out, Hikvision cameras have historically exhibited systemic vulnerabilities. "Their product contains easy to exploit systemic vulnerabilities or worse, uses default credentials," Maynor noted. He further highlighted the difficulty in forensic analysis: "There is no good way to perform forensics or verify that an attacker has been excised. Furthermore, we have not observed any change in Hikvision’s posture to signal an increase in security within their development cycle."
This issue extends beyond Hikvision and is endemic to the rapidly expanding IoT industry. Paul Bischoff, a privacy advocate with Comparitech, elaborated on these systemic challenges. "IoT devices like cameras aren’t always as easy or straightforward to secure as an app on your phone," Bischoff explained. "Updates are not automatic; users need to manually download and install them, and many users might never get the message. Furthermore, IoT devices might not give users any indication that they’re unsecured or out of date. Whereas your phone will alert you when an update is available and likely install it automatically the next time you reboot, IoT devices do not offer such conveniences."
Several factors contribute to this pervasive vulnerability:
- Lack of Automated Updates: Unlike modern operating systems or mobile applications, many IoT devices lack robust, automated update mechanisms. Users are often required to manually download firmware updates from a vendor’s website and follow complex installation procedures, which many lack the technical expertise or time to do.
- Poor User Awareness: Many users and organizations are simply unaware that their IoT devices require regular security updates or that a critical vulnerability even exists. Without proactive notifications from manufacturers, these devices remain in a vulnerable state indefinitely.
- Default Credentials: A significant portion of the problem stems from the use of easily guessable or unchanged default passwords. As Bischoff noted, "Hikvision cameras come with one of a few predetermined passwords out of the box, and many users don’t change these default passwords." Cybercriminals actively scan for devices using these defaults, making them prime targets.
- Limited Visibility and Management: Organizations often have a sprawling and poorly documented inventory of IoT devices, making it difficult to track their security posture, apply patches, or even identify all connected assets.
- Long Lifespan, Short Support: IoT devices, particularly surveillance cameras, are often deployed for many years, sometimes a decade or more. However, vendor support for security updates may be limited to a much shorter period, leaving devices exposed long before they reach their end-of-life.
- Resource Constraints: Smaller businesses or organizations with limited IT resources may struggle to implement comprehensive patch management strategies for their entire IoT ecosystem.
- Supply Chain Risks: Insecure IoT devices can act as weak links in an organization’s broader cybersecurity posture, providing an easy entry point for attackers to traverse into more critical network segments.
Implications and Broader Impact
The continued exposure of tens of thousands of Hikvision cameras carries profound implications across multiple domains:
- National Security: If state-sponsored actors exploit these vulnerabilities, it could lead to widespread espionage, allowing foreign governments to monitor sensitive locations, gather intelligence, or even disrupt critical infrastructure. Given Hikvision’s presence in government facilities and public spaces, this risk is particularly acute.
- Data Privacy: Surveillance cameras capture vast amounts of sensitive visual data. Unauthorized access could lead to severe privacy violations for individuals, exposing private activities or movements.
- Corporate Espionage and Theft: Businesses using these cameras risk intellectual property theft, monitoring of internal operations, or data exfiltration if attackers gain a foothold in their network through a camera.
- Ransomware and Cyberattacks: A vulnerable camera can serve as an initial access point for ransomware gangs or other cybercriminals to launch broader attacks against an organization’s network, leading to significant financial losses and operational disruption.
- Physical Security Breaches: In scenarios where cameras are integrated into physical security systems, their compromise could allow attackers to disable alarms, open access points, or monitor security personnel, facilitating physical intrusions.
- Erosion of Trust: Persistent vulnerabilities and slow patching erode public and organizational trust in IoT devices and their manufacturers, potentially hindering the adoption of beneficial technologies.
Path Forward: Mitigation and Responsibility
Addressing this pervasive issue requires a multi-faceted approach involving manufacturers, organizations, and governments:
- Manufacturer Responsibility: Hikvision, and indeed all IoT manufacturers, must prioritize security by design. This includes developing devices with robust, automated update mechanisms, implementing secure default configurations (e.g., forcing strong password changes upon initial setup), and providing clear, consistent security advisories. As David Maynor suggested, a fundamental shift in Hikvision’s "posture to signal an increase in security within their development cycle" is critical.
- Organizational Vigilance: Organizations deploying IoT devices must implement rigorous asset management, regularly inventorying all connected devices. Comprehensive patch management strategies, including regular vulnerability scanning and firmware updates, are non-negotiable. Network segmentation should be employed to isolate IoT devices from critical internal networks, limiting potential lateral movement for attackers. Strong, unique passwords must be enforced, and default credentials must be changed immediately.
- Governmental and Regulatory Action: Governments can play a crucial role by establishing and enforcing cybersecurity standards for IoT devices. Initiatives like the U.S. IoT Cybersecurity Improvement Act and the EU’s proposed Cyber Resilience Act aim to mandate minimum security requirements for connected devices, promoting secure-by-design principles and clearer security update policies. Continued scrutiny and potential restrictions on high-risk vendors also serve to protect national interests.
- User Education: Increased awareness campaigns are needed to educate end-users and organizations about the importance of IoT security, the risks of unpatched devices, and best practices for securing their connected environments.
The case of CVE-2021-36260 in Hikvision cameras serves as a stark reminder of the enduring and escalating cybersecurity challenges posed by the proliferation of IoT devices. The confluence of critical vulnerabilities, inadequate patch management, and geopolitical tensions creates a volatile landscape where tens of thousands of devices stand as open invitations to cybercriminals and state-sponsored actors alike. Without concerted efforts from all stakeholders, the security of our interconnected world will remain precariously balanced on the edge of widespread, preventable exploitation. The question is not if these cameras will be exploited, but rather when, where, and by whom, and at what ultimate cost.







