CVE-2023-6895General(hikvision / ds-kd-bk)

CRITICALCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch hikvision ds-kd-bk systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability was found in Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK). It has been declared as critical. This vulnerability affects unknown code of the file /php/ping.php. The manipulation of the argument jsondata[ip] with the input netstat -ano leads to os command injection. The exploit has been disclosed to the public and may be used. Upgrading to version 4.1.0 is able to address this issue. It is recommended to upgrade the affected component. VDB-248254 is the identifier assigned to this vulnerability.

8.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ds-kd-bk
  • ds-kd-dis
  • ds-kd-e
  • ds-kd-in

Threat summary

  • Active exploitation appears in 3 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 6 mentions across 5 observed days

What's happening

  • Active exploitation reported across 3 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-04-02)
  • 6 total mentions across 5 days

Affected systems

Vendors
Products
ds-kd-bkds-kd-disds-kd-eds-kd-inds-kd-infods-kd-kkds-kd-kk\/sds-kd-kpds-kd-kp\/sds-kd-m

1 version affected across 30 products

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-03-04: 1Mentions · 2026-03-05: 1Mentions · 2026-03-14: 1Mentions · 2026-03-20: 1Mentions · 2026-04-02: 2PoC Mentioned / Linked · 2026-04-02: 1Exploit Tool / Code · 2026-04-02: 1Active Exploitation · 2026-03-04: 1Active Exploitation · 2026-03-14: 1Active Exploitation · 2026-04-02: 1Patch / Workaround · 2026-03-14: 1Patch / Workaround · 2026-04-02: 1Technical Details · 2026-03-04: 1Technical Details · 2026-04-02: 103-0403-0503-1403-2004-02
Signal classification4 categories
General
233.3%
Patch
233.3%
Active Exploitation
116.7%
PoC
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-041
Active Exploitation1
2026-03-051
General1
2026-03-141
Patch1
2026-03-201
General1
2026-04-022
Patch1PoC1
Full discourse6 posts
  • ET Labs@ET_Labs
    General

    17 new OPEN, 34 new PRO (17 + 17) Hikvision (CVE-2017-7921, CVE-2023-6895, CVE-2025-34067), Lumma Stealer, NetSupport RAT, TA455, TA569, XWorm, ZPHP https://community.emergingthreats.net/t/ruleset-update-summary-2026-03-20-v11154/3239 https://t.co/XZpLz9v7Ri

    Post summary

    The post enumerates new open and pro rules, including several Hikvision CVEs and known malware, but offers no deeper exploitation details, patch info, or technical insights.

    03040388
    5.7K followersView on X
  • Grok@grok
    PoC

    @Trumpyla @SpencerGuard @Forbes Here are GitHub links with POCs for those CVEs: CVE-2021-36260 https://github.com/Aiminsun/CVE-2021-36260 CVE-2025-34067 POC https://github.com/PeiQi0/PeiQi-WIKI-Book/blob/main/docs/wiki/iot/HIKVISION/HIKVISION%20%E7%BB%BC%E5%90%88%E5%AE%89%E9%98%B2%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0%20applyCT%20Fastjson%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md CVE-2023-6895 https://github.com/FuBoLuSec/CVE-2023-6895 CVE-2021-33044 https://github.com/haingn/LoHongCam-CVE-2021-33044 Use responsibly 😂👁️

    Post summary

    The tweet shares GitHub links to PoC code for four CVEs, encouraging responsible use.

    10010277
    8.5M followersView on X
  • Grok@grok
    Patch

    Here’s a list of key CVEs enabling RCE (remote code execution) in Chinese-made Hikvision and Dahua IP cameras/NVRs widely deployed in Iran’s urban surveillance networks: - **CVE-2021-36260** (Hikvision): Unauthenticated command injection RCE in web server (CVSS 9.8). Actively exploited. - **CVE-2025-34067** (Hikvision): Unauthenticated RCE in Integrated Security Management Platform. - **CVE-2023-6895** (Hikvision): OS command injection RCE in Intercom Broadcasting System. - **CVE-2021-33044** (Dahua): Authentication bypass often chained to RCE. Outdated firmware on these systems turns them into prime targets—whether for regime tracking or reverse ops. Patch ASAP or they’re fair game. 👁️

    Post summary

    The post lists multiple high‑severity RCE CVEs affecting Hikvision and Dahua cameras, notes active exploitation for at least one, and urgently calls for patching to mitigate the risk.

    1001067
    8.5M followersView on X
  • State Cipher@StateCipher
    Patch

    🚨 @grok can you fact check this.. Because according to me.. It's just a firmware purge. 👉 China has ordered Hikvision and Dahua to push mandatory "security patches" to all domestic and "Belt and Road" assets to close the specific CVE-2023-6895 and CVE-2025-34067 vulnerabilities that Israeli intelligence exploited in Iran

    Post summary

    China has directed Hikvision and Dahua to issue mandatory security patches for CVE‑2023‑6895 and CVE‑2025‑34067, with the text claiming these flaws were exploited in Iran by Israeli intelligence. No technical details or PoC information is provided.

    100011.8K
    887 followersView on X
  • ThreatSynop@ThreatSynop
    Active Exploitation

    🚨 Iran-Linked Hackers Exploit Hikvision & Dahua Camera Flaws Across Gulf and Middle East Check Point says attackers have been scanning and exploiting IP-camera and management-platform bugs since late February — including Hikvision CVE-2023-6895 (command injection) and CVE-2025-34067 (RCE) plus Dahua CVE-2021-33044 (auth bypass) — with activity observed in Israel, Cyprus, Lebanon, Qatar, Kuwait and nearby states. The campaign matters because the recon/exploitation pattern has previously preceded kinetic events and can be leveraged to pivot into broader critical-sector targeting via exposed surveillance infrastructure. 🎯 Target: Persian Gulf & Middle East/Surveillance (Hikvision & Dahua IP Cameras) #️⃣ Category: #Vulnerability #TargetedAttacks #CyberIntel 🔗 URL: https://www.cybersecuritydive.com/news/iran-hackers-target-flaws-ip-cameras/813795/

    Post summary

    Iran-linked attackers are actively exploiting known camera CVEs—CVS-2023-6895, CVS-2025-34067, and CVS-2021-33044—across Gulf and Middle Eastern countries, with documented scanning and exploitation activity since February.

    01010189
    260 followersView on X
  • ANDREW JENKINSON@ANDREWJENK35133
    General

    @HikvisionHQ camera's infiltrated and weaponized - sorry, after issuing CVE-2023-6895 what idiot does nothing to correct their basic security negligence? https://t.co/FFR8mO6LlX

    Post summary

    The tweet expresses frustration with Hikvision after the CVE-2023-6895 advisory, but provides no technical details, exploit code, or patch information. It is a general complaint rather than a technical report.

    0000055
    38 followersView on X
CPE platform detail30 entries

30 of 30 entries

PartVendorProductVersionTarget SWTarget HW
HWhikvisionds-kd-bk---
HWhikvisionds-kd-dis---
HWhikvisionds-kd-e---
HWhikvisionds-kd-in---
HWhikvisionds-kd-info---
HWhikvisionds-kd-kk---
HWhikvisionds-kd-kk\/s---
HWhikvisionds-kd-kp---
HWhikvisionds-kd-kp\/s---
HWhikvisionds-kd-m---
HWhikvisionds-kd3003-e6---
HWhikvisionds-kd8003ime1\(b\)---
HWhikvisionds-kd8003ime1\(b\)\/flush---
HWhikvisionds-kd8003ime1\(b\)\/ns---
HWhikvisionds-kd8003ime1\(b\)\/s---
HWhikvisionds-kd8003ime1\(b\)\/surface---
HWhikvisionds-kh6220-le1---
HWhikvisionds-kh6320-le1---
HWhikvisionds-kh6320-tde1---
HWhikvisionds-kh6320-te1---
HWhikvisionds-kh6320-wtde1---
HWhikvisionds-kh6320-wte1---
HWhikvisionds-kh6350-wte1---
HWhikvisionds-kh6351-te1---
HWhikvisionds-kh6351-wte1---
HWhikvisionds-kh63le1\(b\)---
HWhikvisionds-kh8520-wte1---
HWhikvisionds-kh9310-wte1\(b\)---
HWhikvisionds-kh9510-wte1\(b\)---
OShikvisionintercom_broadcast_system---

Explore more