Multiple Hikvision Flaws Allow Device Disruption via Crafted Network Packets
Hikvision has identified two critical buffer overflow vulnerabilities in its security devices, potentially allowing network-based attackers to cause device malfunctions.
Hikvision has identified two critical buffer overflow vulnerabilities in its security devices, potentially allowing network-based attackers to cause device malfunctions.
The security vulnerabilities, designated as CVE-2025-66176 and CVE-2025-66177, impact specific access control products and video recording systems. Both issues arise from stack overflow problems in the device search and discovery feature.
CVE ID Affected Products Base Score
CVE-2025-66176 Partial Access Control Series Products 8.8
CVE-2025-66177 Partial NVR, DVR, CVR, IPC Series Products 8.8
The security vulnerabilities, designated as CVE-2025-66176 and CVE-2025-66177, impact specific access control products and video recording systems.
Attackers on the same local area network can exploit these vulnerabilities by sending specially crafted packets to unpatched devices, leading to system disruptions without the need for authentication or user interaction.
The vulnerabilities have been assigned CVSS v3.1 base scores of 8.8, indicating high severity. The vector string (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) suggests that the attack vectors are adjacent network-accessible, with low attack complexity, no privileges required, and no user interaction necessary. This can potentially impact confidentiality, integrity, and availability.
The first vulnerability affects Hikvision's Access Control Series Products, while the second targets Network Video Recorders, Digital Video Recorders, Central Video Recorders, and IP Cameras.
Hikvision has released a detailed list of specific affected models through its security advisory portal .
Users are advised to immediately download the latest firmware versions from Hikvision’s official support download center. The company stresses the importance of applying updates promptly to mitigate potential network-based attacks, especially in enterprise and critical infrastructure settings where these devices are used for physical security monitoring.
Network administrators should consider segmenting surveillance networks, limiting device discovery protocols to trusted zones, and monitoring for unusual traffic patterns that may indicate exploitation attempts until patching is complete.
Based on reporting by GBHackers.
