CVE-2026-0709

Some Hikvision Wireless Access Points are vulnerable to authenticated command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution.
Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) Algunos Puntos de Acceso Inalámbricos Hikvision son vulnerables a la ejecución de comandos autenticada debido a una validación de entrada insuficiente. Atacantes con credenciales válidas pueden exploit esta falla enviando paquetes manipulados que contienen comandos maliciosos a los dispositivos afectados, lo que lleva a la ejecución arbitraria de comandos.

27 Feb 2026, 15:16

Type Values Removed Values Added
CWE CWE-78

30 Jan 2026, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-30 11:15

Updated : 2026-04-15 00:35


NVD link : CVE-2026-0709

Mitre link : CVE-2026-0709

CVE.ORG link : CVE-2026-0709


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')