CVE-2026-3828Disclosure

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Some Hikvision switch products (discontinued since December 2023) are vulnerable to authenticated remote command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 6 signals
  • Disclosure: 7 classified signals
  • Peaked 4d ago at 2 mentions (2026-05-09); latest day: 1
  • 7 total mentions across 5 days

Deep dive

Activity timeline7 mentions / 5d
01122Mentions · 2026-05-09: 2Mentions · 2026-05-10: 1Mentions · 2026-05-11: 2Mentions · 2026-05-12: 1Mentions · 2026-05-20: 1Technical Details · 2026-05-09: 2Technical Details · 2026-05-10: 1Technical Details · 2026-05-11: 2Technical Details · 2026-05-12: 105-0905-1005-1105-1205-20
Signal classification1 categories
Disclosure
7100.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-092
Disclosure2
2026-05-101
Disclosure1
2026-05-112
Disclosure2
2026-05-121
Disclosure1
2026-05-201
Disclosure1
Full discourse7 posts
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidad en productos Hikvision ❗ CVE-2026-3828 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-hikvision-3/ https://t.co/pIcfBJUcHd

    Post summary

    A new CVE-2026-3828 vulnerability affecting Hikvision products has been disclosed, with links provided for further details.

    00001129
    6.7K followersView on X
  • Vignesh_Pravin@VigneshVic23698
    Disclosure

    Hikvision Switch Flaw CVE-2026-3828 Allows Remote Code Execution https://thecybrdef.com/hikvision-switch-cve-2026-3828-rce-vulnerability/ #Cybernews #Cyberupdate #Cybersecuirty

    Post summary

    The text announces the discovery of CVE‑2026‑3828, a remote code execution flaw in Hikvision switches, but does not provide PoC details, active exploitation evidence, patch information, or evidence of a false positive.

    0000043
    2 followersView on X
  • Harishraam@unknownmatter19
    Disclosure

    Hikvision Switch Flaw CVE-2026-3828 Allows Remote Code Execution https://thecybrdef.com/hikvision-switch-cve-2026-3828-rce-vulnerability/ #Cybernews #Cyberupdate #Cybersecuirty

    Post summary

    The text announces a newly identified remote code execution flaw in Hikvision switches (CVE-2026-3828) with basic details but no evidence of exploitation or mitigation.

    0000041
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-3828 📊 Severity: 7.2 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-3828 #CVE-2026-3828 #CVE #High #CyberSecurity #InfoSec https://t.co/FETlR6eFlg

    Post summary

    The text announces the discovery of CVE‑2026‑3828, highlighting a high‑severity (7.2) vulnerability affecting multiple products, with a link to the NVD entry for further details.

    0000035
    157 followersView on X
  • selva@SelvaKtm2
    Disclosure

    Hikvision Switch Flaw CVE-2026-3828 Allows Remote Code Execution https://thecybrdef.com/hikvision-switch-cve-2026-3828-rce-vulnerability/ #Cybernews #Cyberupdate #Cybersecuirty https://t.co/ZIEWN4fnAj

    Post summary

    The tweet announces a newly disclosed CVE‑2026‑3828 vulnerability in Hikvision Switch devices that permits remote code execution, with no mention of PoC, exploitation, or patch details.

    0000036
    5 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3828 Some Hikvision switch products (discontinued since December 2023) are vulnerable to authenticated remote command execution due to insufficient input validation. Attacke… https://www.cve.org/CVERecord?id=CVE-2026-3828

    Post summary

    CVE-2026-3828 affects discontinued Hikvision switch products, allowing authenticated remote command execution via insufficient input validation; no PoC, exploit, or patch details are provided.

    0000050
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3828 Authenticated Remote Command Execution in Hikvision Switch Products via Insufficient Input Validation https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3828

    Post summary

    The text announces CVE-2026-3828, a vulnerability allowing authenticated remote command execution in Hikvision switches due to insufficient input validation, with no evidence of PoC, exploit code, active attacks, or patch information.

    0000044
    4.0K followersView on X

Explore more