CVE-2025-66177Exploit

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

There is a Buffer overflow Vulnerability in the device Search and Discovery feature of Hikvision NVR/DVR/CVR/IPC models. If exploited, an attacker on the same local area network (LAN) could cause the device to malfunction by sending specially crafted packets to an unpatched device.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-121

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 1 signal
  • Peaked 1d ago at 1 mentions (2026-04-15); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-15: 1Mentions · 2026-05-24: 1PoC Mentioned / Linked · 2026-04-15: 1PoC Mentioned / Linked · 2026-05-24: 1Exploit Tool / Code · 2026-04-15: 1Exploit Tool / Code · 2026-05-24: 1Technical Details · 2026-04-15: 104-1505-24
Signal classification1 categories
Exploit
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Pedro Guillén Núñez@_p3r1k0_
    Exploit

    Acabamos de lanzar @EinyelLA y @_p3r1k0_ de subir el módulo de Metasploit para el CVE-2025-66177 en firmware Hikvision NVR (v4.72/v4.83). https://github.com/ang3lL/CVE-2025-66177/tree/main

    Post summary

    A Metasploit module for CVE-2025-66177 targeting Hikvision NVR firmware has been released and is available on GitHub, but there is no indication of current active exploitation or patches.

    030821.2K
    232 followersView on X
  • Ekoparty | Hacking everything@ekoparty
    Exploit

    EKO Miami 2026 Main Track Talks 🔥 🗣️ “Desde el Firmware al RCE: Atacando NVRs de Hikvision” by @EinyelLA and Pedro Guillén Núñez. 📌 This talk presents a detailed technical investigation into the discovery of two 0-days related to CVE-2025-66177 in Hikvision NVR devices, which also affect other products from the same brand and its subsidiaries. It covers the entire research process, from firmware acquisition, decryption, emulation, and both static and dynamic analysis for vulnerability discovery and exploitation, to obtaining a real device, achieving full system compromise, and establishing persistence through memory addresses and ROP. The exploit has been adapted as a Metasploit module, with the ability to automatically identify the target firmware version and support multiple vulnerable versions. 🎯 During the talk, a live demonstration will be performed on a real physical device, and the exploit will be released. This research brings significant value to the community, as it thoroughly documents a complete methodology for discovering and exploiting 0-days in embedded devices, which can be extrapolated to similar environments. It is a highly technical talk, aimed at offensive and advanced security research profiles, with deep focus on both reverse engineering and exploitation of embedded systems. ✅ This talk will be delivered in spanish. 📅 Ekoparty Miami | May 21–22, 2026 🎟️ Get your ticket now and don’t miss out! >> http://ekoparty.org/miami - Charlas Main Track EKO Miami 2026 🔥 🗣️ “Desde el Firmware al RCE: Atacando NVRs de Hikvision” dictada por @EinyelLA y Pedro Guillén Núñez. 📌 Esta charla presenta una investigación técnica detallada sobre el descubrimiento de 2 0 días relativo a CVE-2025-66177 en dispositivos NVR de Hikvision y que también afecta a otros productos de la misma marca y fabricantes subsidiarios. Abarca todo el proceso de investigación, desde la obtención del firmware, descifrado, emulación, análisis estático y dinámico para el descubrimiento de las vulnerabilidades y la explotación, hasta la adquisición de un dispositivo real, compromiso total del sistema y obtención de persistencia en el mismo a direcciones de memoria y ROP. El exploit ha sido adaptado como módulo para Metasploit, con capacidad para identificar automáticamente la versión de firmware objetivo y soportar varias versiones vulnerables. 🎯 Durante la charla se realizará una demostración en vivo sobre un dispositivo físico real, y el mismo exploit será publicado. Esta investigación aporta un gran valor a la comunidad, ya que documenta de forma detallada una metodología completa para el descubrimiento y explotación de 0-days en dispositivos embebidos, extrapolable a otros entornos similares. Se trata de una charla altamente técnica, orientada a perfiles ofensivos y de investigación avanzada en seguridad, que profundiza tanto en ingeniería inversa como en explotación sobre sistemas embebidos. ✅ Esta charla será dictada en español. 📅 Ekoparty Miami I 21 y 22 de mayo 2026 🎟️ ¡Conseguí tu entrada ahora y no te quedes afuera! >> http://ekoparty.org/miami

    Post summary

    The session discloses two 0‑day RCE vulnerabilities in Hikvision NVRs (CVE‑2025‑66177), demonstrates a Metasploit module for exploitation, and plans to release the exploit code, highlighting a ready‑to‑use attack vector.

    14030778
    25.4K followersView on X

Explore more