CVE Intel / CVE-2021-36260

CVE-2021-36260

ds-2cd2021g1-i\(w\) · hikvision
CISA KEVexploited on our sensorsCritical network detectable

What it is

A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability to launch a command injection attack by sending some messages with malicious commands.

Live exploitation on the huntback network (30 days)

16
attempts captured
1
distinct source IPs
2026-09-23
last seen
huntback carries a network signature for this CVE. Exploitation attempts are detected on the decoy fleet in real time.

How huntback helps

Deploy a decoy that emulates ds-2cd2021g1-i\(w\) and you will see every attempt at this CVE the moment it lands, with the full payload, the attacker's infrastructure, and any stage-2 loader. Then huntback can scan the attacker back.

CVSSn/a Critical
EPSS1.00 (99% pct)
In CISA KEVyes
Publishedn/a
Network detectableyes, signatured