Tens of thousands of cameras have failed to patch a critical, 11-month-old CVE, leaving thousands of organizations exposed.

The global landscape of internet-connected surveillance equipment faces a significant security reckoning as new data confirms that over 80,000 Hikvision surveillance cameras remain susceptible to a critical command injection vulnerability nearly a year after its initial disclosure. The flaw, tracked as CVE-2021-36260, carries a CVSS score of 9.8 out of 10, categorizing it as a critical risk that allows unauthenticated remote attackers to execute arbitrary code on the affected hardware. Despite the passage of 11 months since the vulnerability was identified and a patch was made available by the manufacturer, the persistence of these vulnerable devices across 100 countries underscores a deepening crisis in the security posture of the Internet of Things (IoT) ecosystem.
Chronology of the Vulnerability
The lifecycle of CVE-2021-36260 began in the fall of 2021, when cybersecurity researchers identified that a command injection flaw existed in the web server of Hikvision surveillance cameras. Because the vulnerability resides in the web interface, it provides a direct gateway for unauthorized actors to gain full control over the camera’s operating system.
By September 2021, the vulnerability was formally documented and NIST (National Institute of Standards and Technology) assigned it the maximum severity rating. Hikvision released firmware updates to remediate the issue shortly thereafter. However, the remediation effort has been met with widespread inertia. Recent research conducted by Cyfirma indicates that even as of the third quarter of 2022, tens of thousands of these units remain active on the public-facing internet, unpatched and fully exposed to exploitation. This timeline reveals a concerning gap between the discovery of a catastrophic security flaw and the practical application of defensive measures by end-users and enterprise administrators.
The Scope of the Exposure
Hikvision, a Chinese state-owned enterprise, stands as one of the world’s largest manufacturers of video surveillance equipment. Its global footprint is vast, with millions of devices deployed in government facilities, critical infrastructure, corporate offices, and private residences. In the United States, the company has faced significant regulatory scrutiny; in 2019, the Federal Communications Commission (FCC) labeled the company an "unacceptable risk to U.S. national security," citing potential vulnerabilities and the firm’s close ties to the Chinese state.
The persistence of CVE-2021-36260 is not merely a theoretical risk. Cyber threat intelligence analysts have documented multiple instances of malicious actors actively collaborating on dark web forums—specifically those operating in Russian-speaking circles—to develop and refine exploits for this exact vulnerability. The forums have seen a rise in the trade of leaked credentials associated with Hikvision devices, providing attackers with a "turnkey" method to bypass authentication before deploying the command injection exploit.
Systemic Failures in IoT Security
The failure to patch 80,000 devices highlights deep-seated structural issues within the IoT industry. Unlike desktop operating systems or mobile platforms, which have matured to include robust, automated, and often mandatory update mechanisms, IoT devices frequently operate in a "set it and forget it" mode.
David Maynor, senior director of threat intelligence at Cybrary, suggests that the problem extends far beyond the simple failure to click an "update" button. "Hikvision’s product contains easy-to-exploit systemic vulnerabilities, or worse, relies on default credentials," Maynor stated. "There is no standardized way to perform forensic analysis on these devices, nor is there a verifiable method to confirm that an attacker has been successfully excised from the system once a breach has occurred."
The lack of visibility is a critical bottleneck. In many enterprise environments, these cameras are managed by facility managers or third-party security firms rather than IT security professionals. Consequently, the firmware update, even when available, often fails to reach the device. Furthermore, Hikvision’s development cycle has faced criticism for failing to adopt "security by design" principles. As Maynor noted, observers have not seen a significant shift in the company’s security posture that would suggest a maturing development cycle or a more proactive approach to vulnerability management.
The Role of User Oversight and Industry Standards
The challenge of securing IoT hardware is exacerbated by the lack of user-facing notifications. Modern smartphones serve as the gold standard for security hygiene, pushing clear, actionable alerts to users when a system update is pending, and often automating the installation process during idle hours. IoT devices, by contrast, are largely "silent." Most cameras provide no interface to warn a user that the device is running outdated, vulnerable software.
Privacy advocates, such as Paul Bischoff of Comparitech, emphasize that the industry must shift the burden of security away from the end-user. "Updates are not automatic; users need to manually download and install them, and many users might never get the message," Bischoff explained. "While it is easy to blame users for failing to update, the industry has failed to provide the necessary tools for users to secure their devices effectively."
This issue is compounded by the widespread use of default, weak, or hard-coded credentials. Despite years of warnings from security agencies like the FBI and CISA, many administrators fail to perform the basic task of changing factory-set passwords. When paired with a searchable, internet-facing vulnerability, these devices become low-hanging fruit for scanners using tools like Shodan or Censys, which allow attackers to map and target vulnerable hardware globally within minutes.
Strategic and Geopolitical Implications
The potential for exploitation of these devices is significant, particularly when considering the motives of advanced persistent threat (APT) groups. The Cyfirma report points to the risk of Chinese-affiliated groups—such as MISSION2025/APT41 and APT10—as well as various Russian threat actors, potentially leveraging these cameras for espionage or surveillance.
Because these cameras are often installed in high-security areas, an attacker who gains control of the video feed or the camera’s internal network connection could potentially conduct reconnaissance, pivot into the host organization’s internal network, or disrupt critical operations. The geopolitical tension surrounding Chinese-manufactured technology adds a layer of complexity; for many Western organizations, the discovery of this unpatched vulnerability serves as a stark reminder of the risks associated with hardware that resides in the blind spot of traditional enterprise security programs.
Addressing the Deficit
Moving forward, industry analysts suggest that the solution to the Hikvision crisis and broader IoT vulnerabilities must be multifaceted. First, manufacturers must implement mandatory, automated update systems that do not require manual intervention by the end-user. Second, there must be a move toward more transparent security auditing, where vulnerabilities are not just disclosed but are actively pushed to registered owners via cloud-based management platforms.
Third, regulatory bodies and national security agencies may need to implement stricter requirements for the procurement of IoT devices in critical infrastructure. The current status quo, where tens of thousands of devices are left exposed for nearly a year, is a failure that highlights the need for better oversight.
Ultimately, the 80,000 unpatched Hikvision cameras represent a latent threat that could be mobilized at any time. As cybercriminals and state-sponsored actors continue to refine their methods for exploiting the IoT, the window for organizations to audit their physical security infrastructure is closing. Without a fundamental shift in how IoT manufacturers handle vulnerability disclosures and how enterprises monitor their hardware, the cycle of exploitation is likely to continue, leaving a massive, unpatched attack surface vulnerable to the next wave of global cyber-operations. The reality remains that in the interconnected age, a single unpatched camera in a remote corner of an office building can provide the foothold needed for a devastating breach of the entire corporate network.







