CVE-2017-7921 – Critical Authentication Bypass in Hikvision IP Cameras

Key takeaways

  • Severity: Critical (CVSS 3.0 base score 10.0)
  • Impact: Unauthenticated access to configuration files, user credentials, Wi‑Fi keys, live video snapshots, and the ability to use the device as a foothold for lateral movement.
  • Affected: Multiple Hikvision IP cameras, NVR/DVR models (e.g., DS‑2CD2xx series) running firmware prior to the latest patches.
  • Active exploitation: Confirmed in the wild; listed in the CISA KEV catalog with a mitigation deadline of 2026‑03‑26.
  • Remediation: Apply the vendor patch, enforce strong credentials, and isolate devices on a dedicated VLAN.

Overview

The vulnerability identified as CVE-2017-7921 is an improper authentication flaw (CWE‑287) in the firmware of many Hikvision IP cameras, network video recorders (NVR) and digital video recorders (DVR). By sending a specially crafted HTTP GET request that includes a Base64‑encoded auth parameter, an attacker can bypass the login screen entirely and gain administrator‑level access.

The flaw was first disclosed in 2017, but recent activity shows that threat actors have revived the exploit to harvest configuration files, Wi‑Fi credentials, and live video streams. The United States CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog in March 2026, confirming active exploitation.


Technical Details

Exploit Mechanics

The vulnerable endpoint accepts an auth query parameter that is decoded by the device and used as credentials without proper validation. A typical malicious request looks like:

GET /System/deviceInfo?auth=YWRtaW46MTEK HTTP/1.1
Host: <camera‑ip>
  • YWRtaW46MTEK is the Base64 representation of admin:11.
  • When the device decodes the string, it treats it as a valid login, granting full administrative rights.

Because the endpoint is hidden and undocumented, many administrators never see it in normal operation. Attackers automate scans across IP ranges, appending the auth parameter to various management URLs (e.g., /System/configurationFile, /Security/users, /onvif-http/snapshot). Successful responses return HTTP 200 with sensitive data.

Observed Exploit Activity

Honeypot data collected between 2018 and 2025 shows thousands of attempts. Below is a snapshot of the most‑targeted URLs and total exploit attempts:

Endpoint (GET)First SeenMost RecentTotal Attempts
/System/configurationFile?auth=YWRtaW46MTEK2018‑08‑182025‑09‑236 720
/Security/users?auth=YWRtaW46MTEK2017‑12‑142025‑09‑232 293
/system/deviceInfo?auth=YWRtaW46MTEK2021‑03‑092025‑09‑232 002
/onvif-http/snapshot?auth=YWRtaW46MTEK2018‑09‑092025‑09‑23445
/Security/users/1?auth=YWRtaW46MTEK2020‑09‑252023‑02‑04727
/Streaming/channels/1/picture/?auth=YWRtaW46MTEKYOBA2017‑10‑062017‑10‑066
/ISAPI/Security/users?auth=YWRtaW46MTEK2025‑04‑092025‑04‑292

Successful exploitation yields:

  • Full device configuration (including admin passwords and Wi‑Fi keys)
  • User account listings
  • Live video snapshots
  • Ability to change settings or install malicious firmware

Severity & CVSS

MetricValue
CVSS v3.0 Base Score10.0
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SeverityCritical
CWECWE‑287 (Improper Authentication)
NVD Published2017‑05‑05
CISA KEVYes (added 2026‑03‑05)

The CVSS vector reflects Network exposure, Low attack complexity, No privileges required, and Complete impact on confidentiality, integrity, and availability.


Affected Products

The vulnerability impacts a wide range of Hikvision devices. Representative models include:

Product CategoryExample Models
IP CamerasDS‑2CD2xx2F‑I, DS‑2CD2xx0F‑I, DS‑2CD4x2xFWD series
NVR/DVRDS‑2DFx series, DS‑2CD63xx series
Firmware VersionsV5.2.0 build 140721 → V5.4.5 build 160928 (and intermediate builds)

For the full list of affected products and firmware versions, see the official Hikvision advisory or the detailed CVE entry at https://vulnsocial.com/cve/CVE-2017-7921.


Impact Assessment

Impact DimensionDescription
ConfidentialityAttackers can download configuration files, Wi‑Fi passwords, and stored video recordings, exposing sensitive operational data.
IntegrityFull admin rights allow modification of device settings, firmware replacement, or insertion of malicious code.
AvailabilityCompromised cameras can be used in DDoS botnets or as a pivot point to disrupt other network services.

The combination of unauthenticated access and privilege escalation makes CVE-2017-7921 a high‑impact threat for any organization that relies on Hikvision surveillance equipment.


Remediation & Mitigation

  1. Apply the latest firmware patch. Download updates directly from the official Hikvision support portal and verify checksums.
  2. Disable URL‑based authentication. Block or remove any management URLs that accept the auth parameter.
  3. Enforce strong, unique credentials. Replace default admin passwords (e.g., admin:11) with complex, randomly generated passwords.
  4. Network segmentation. Place all surveillance devices on a dedicated VLAN or isolated subnet; restrict inbound traffic to trusted management hosts.
  5. Enable HTTPS with proper certificate validation. Prefer digest or token‑based authentication over clear‑text credentials.
  6. Monitor logs for suspicious auth= parameters. Alert on any HTTP 200 responses to management endpoints that include the auth query string.
  7. Consider decommissioning legacy devices that no longer receive security updates.

The CISA binding operational directive (BOD 22‑01) requires federal agencies to complete remediation by 2026‑03‑26; the same timeline is a good benchmark for private sector organizations.


Bottom Line

CVE-2017-7921 is a Critical authentication bypass affecting a broad range of Hikvision cameras and recorders. Active exploitation in the wild and inclusion in the CISA KEV catalog make it an urgent priority. Immediate patch deployment, credential hardening, and network isolation are essential to prevent data theft, lateral movement, and potential DDoS abuse.

For live threat intelligence and community discussion, visit the VulnSocial page: https://vulnsocial.com/cve/CVE-2017-7921.


References