CVE-2026-57599
MEDIUM
6.6
CVSS 3.1
Description
There is a privilege escalation vulnerability in some Hikvision cameras. Due to incorrect permission allocation in the device program, attackers can escalate privileges and gain full control of the device after authenticating via SSH.
Metadata
Severity & Metrics
6.6
MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Hikvision | DS-2CD Series | — | https://www.hikvision.com/en/support/download/firmware/security-firmware-download/ |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-269 | adp | CWE-269 Improper Privilege Management |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 6.6 | MEDIUM | 3.1 | cna | CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H |
References (1)