There is a privilege escalation vulnerability in some Hikvision DVR products. Due to the improper implementation of authentication for the serial port, an attacker with physical access could exploit this vulnerability by connecting to the affected products and gaining access to an unrestricted shell environment.
References
Configurations
History
23 Dec 2025, 21:45
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.hikvision.com/en/support/cybersecurity/security-advisory/serial-port-privilege-escalation-vulnerabilities-in-some-hikvision-nvr-devices/ - Vendor Advisory | |
| CPE | cpe:2.3:h:hikvision:ds-7204hghi-f1:-:*:*:*:*:*:*:* cpe:2.3:o:hikvision:ds-7104hghi-f1_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:hikvision:ds-7204hghi-f1_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:hikvision:ds-7104hghi-f1:-:*:*:*:*:*:*:* |
|
| First Time |
Hikvision ds-7104hghi-f1
Hikvision Hikvision ds-7104hghi-f1 Firmware Hikvision ds-7204hghi-f1 Firmware Hikvision ds-7204hghi-f1 |
19 Dec 2025, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-269 |
19 Dec 2025, 07:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-19 07:16
Updated : 2025-12-23 21:45
NVD link : CVE-2025-66173
Mitre link : CVE-2025-66173
CVE.ORG link : CVE-2025-66173
JSON object : View
Products Affected
hikvision
- ds-7104hghi-f1_firmware
- ds-7204hghi-f1_firmware
- ds-7104hghi-f1
- ds-7204hghi-f1
CWE
CWE-269
Improper Privilege Management
