A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability to launch a command injection attack by sending some messages with malicious commands.
https://thehackernews.com/2026/03/iran-linked-muddywater-hackers-target.html
https://www.theregister.com/2026/03/04/iranian_hacking_attempts_ip_cameras/
https://www.infosecurity-magazine.com/news/webcams-vulnerable-hiatusrat-fbi/
https://thehackernews.com/2024/12/cisa-and-fbi-raise-alerts-on-exploited.html