Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Hikvision Wireless AP Flaw Could Let Attackers Run Arbitrary Commands

Hikvision has identified a significant command execution vulnerability impacting multiple models of its wireless access points. This vulnerability could allow authenticated attackers to execute arbitrary commands on affected devices.

Hikvision has identified a significant command execution vulnerability impacting multiple models of its wireless access points. This vulnerability could allow authenticated attackers to execute arbitrary commands on affected devices.

An advisory was issued on Tue, Jan 30, 2026, highlighting the security flaw and advising customers to implement patches without delay.

The vulnerability, designated as CVE-2026-0709, is due to inadequate input validation in the firmware of Hikvision's wireless access points.

With valid credentials, attackers can exploit this vulnerability by sending maliciously crafted packets to compromised devices, allowing the execution of commands and bypassing security protocols.

Model Vulnerable Version Patched Version CVE ID

DS-3WAP521-SI V1.1.6303 build250812 and earlier V1.1.6601 build251223 CVE-2026-0709

DS-3WAP522-SI V1.1.6303 build250812 and earlier V1.1.6601 build251223 CVE-2026-0709

Hikvision has identified a significant command execution vulnerability impacting multiple models of its wireless access points.
Olivia Harper · Thehackingpost

DS-3WAP621E-SI V1.1.6303 build250812 and earlier V1.1.6601 build251223 CVE-2026-0709

DS-3WAP622E-SI V1.1.6303 build250812 and earlier V1.1.6601 build251223 CVE-2026-0709

DS-3WAP623E-SI V1.1.6303 build250812 and earlier V1.1.6601 build251223 CVE-2026-0709

DS-3WAP622G-SI V1.1.6303 build250812 and earlier V1.1.6601 build251223 CVE-2026-0709

Exploiting this vulnerability requires network access and valid authentication credentials, with no user interaction needed.

Advertisement

Hikvision has ranked this vulnerability with a CVSS v3.1 base score of 7.2, indicating high severity. The CVSS vector (AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H) suggests the flaw is remotely exploitable, has low attack complexity, and requires high-level privileges.

This vulnerability affects the confidentiality, integrity, and availability of impacted systems and involves six models from Hikvision's DS-3WAP series. Devices running firmware version V1.1.6303 build 250812 or earlier are vulnerable.

A patched firmware version, V1.1.6601 build 251223, has been released to address this issue. Organizations utilizing the affected access points should update to this version immediately. Patches are available through Hikvision's official support portal.

The vulnerability was identified and reported by an independent security researcher to Hikvision's Security Response Center.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories