Exploit discussion active in current signal (1 latest mentions)
Immediate actions
Prioritize remediation for affected systems immediately
Hunt for exploitation attempts and persistence artifacts
Increase monitoring for publicly documented tradecraft
Track advisory updates for patch or workaround availability
Recommended action window: High priority (within 72h)
NVD description
There is a Buffer overflow Vulnerability in the device Search and Discovery feature of Hikvision NVR/DVR/CVR/IPC models. If exploited, an attacker on the same local area network (LAN) could cause the device to malfunction by sending specially crafted packets to an unpatched device.
Acabamos de lanzar @EinyelLA y @_p3r1k0_ de subir el módulo de Metasploit para el CVE-2025-66177 en firmware Hikvision NVR (v4.72/v4.83).
https://github.com/ang3lL/CVE-2025-66177/tree/main
Post summary
A Metasploit module for CVE-2025-66177 targeting Hikvision NVR firmware has been released and is available on GitHub, but there is no indication of current active exploitation or patches.
EKO Miami 2026 Main Track Talks 🔥
🗣️ “Desde el Firmware al RCE: Atacando NVRs de Hikvision” by @EinyelLA and Pedro Guillén Núñez.
📌 This talk presents a detailed technical investigation into the discovery of two 0-days related to CVE-2025-66177 in Hikvision NVR devices, which also affect other products from the same brand and its subsidiaries.
It covers the entire research process, from firmware acquisition, decryption, emulation, and both static and dynamic analysis for vulnerability discovery and exploitation, to obtaining a real device, achieving full system compromise, and establishing persistence through memory addresses and ROP.
The exploit has been adapted as a Metasploit module, with the ability to automatically identify the target firmware version and support multiple vulnerable versions.
🎯 During the talk, a live demonstration will be performed on a real physical device, and the exploit will be released.
This research brings significant value to the community, as it thoroughly documents a complete methodology for discovering and exploiting 0-days in embedded devices, which can be extrapolated to similar environments. It is a highly technical talk, aimed at offensive and advanced security research profiles, with deep focus on both reverse engineering and exploitation of embedded systems.
✅ This talk will be delivered in spanish.
📅 Ekoparty Miami | May 21–22, 2026
🎟️ Get your ticket now and don’t miss out! >> http://ekoparty.org/miami
-
Charlas Main Track EKO Miami 2026 🔥
🗣️ “Desde el Firmware al RCE: Atacando NVRs de Hikvision” dictada por @EinyelLA y Pedro Guillén Núñez.
📌 Esta charla presenta una investigación técnica detallada sobre el descubrimiento de 2 0 días relativo a CVE-2025-66177 en dispositivos NVR de Hikvision y que también afecta a otros productos de la misma marca y fabricantes subsidiarios.
Abarca todo el proceso de investigación, desde la obtención del firmware, descifrado, emulación, análisis estático y dinámico para el descubrimiento de las vulnerabilidades y la explotación, hasta la adquisición de un dispositivo real, compromiso total del sistema y obtención de persistencia en el mismo a direcciones de memoria y ROP.
El exploit ha sido adaptado como módulo para Metasploit, con capacidad para identificar automáticamente la versión de firmware objetivo y soportar varias versiones vulnerables.
🎯 Durante la charla se realizará una demostración en vivo sobre un dispositivo físico real, y el mismo exploit será publicado.
Esta investigación aporta un gran valor a la comunidad, ya que documenta de forma detallada una metodología completa para el descubrimiento y explotación de 0-days en dispositivos embebidos, extrapolable a otros entornos similares. Se trata de una charla altamente técnica, orientada a perfiles ofensivos y de investigación avanzada en seguridad, que profundiza tanto en ingeniería inversa como en explotación sobre sistemas embebidos.
✅ Esta charla será dictada en español.
📅 Ekoparty Miami I 21 y 22 de mayo 2026
🎟️ ¡Conseguí tu entrada ahora y no te quedes afuera! >> http://ekoparty.org/miami
Post summary
The session discloses two 0‑day RCE vulnerabilities in Hikvision NVRs (CVE‑2025‑66177), demonstrates a Metasploit module for exploitation, and plans to release the exploit code, highlighting a ready‑to‑use attack vector.