A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability to launch a command injection attack by sending some messages with malicious commands.
https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html
https://thehackernews.com/2026/06/new-sharkloader-malware-deploys-cobalt.html
https://securelist.com/strikeshark-campaign/120326/
https://thehackernews.com/2026/03/iran-linked-muddywater-hackers-target.html
https://www.theregister.com/2026/03/04/iranian_hacking_attempts_ip_cameras/
https://www.infosecurity-magazine.com/news/webcams-vulnerable-hiatusrat-fbi/
https://thehackernews.com/2024/12/cisa-and-fbi-raise-alerts-on-exploited.html
https://github.com/sylhetyhackvenger/HIKRAVEN
https://github.com/Exhunterx/eyesharvester
https://github.com/0x5477/Ingram-Pro
https://github.com/Erik-Castro/DevSecurity
https://github.com/mrhenrike/EmbedXPL-Forge
https://github.com/AlexSerdukov12/IoT-Camera-RCE-Lab
https://github.com/saaydmr/hikvision-exploiter
https://github.com/yanxinwu946/hikvision-unauthenticated-rce-cve-2021-36260
https://github.com/aengussong/hikvision_probe
https://github.com/hheeyywweellccoommee/hikvision_brute-jnrxx
https://github.com/r3t4k3r/hikvision_brute
https://github.com/34zY/APT-Backpack
https://github.com/tuntin9x/CheckHKRCE
https://github.com/rabbitsafe/CVE-2021-36260
https://www.cyfirma.com/wp-content/uploads/2022/08/HikvisionSurveillanceCamerasVulnerabilities.pdf
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-36260
http://packetstormsecurity.com/files/164603/Hikvision-Web-Server-Build-210702-Command-Injection.html