Hikvision DS-3WAP622G-SI
cpe:2.3:h:hikvision:ds-3wf0ac-2nt:*:*:*:*:*:*:*, +1 more
- <= V1.1.5402 build241014 (E2254P02)
- <= V1.1.5400 build240814 (E2254)
A vulnerability allowing authenticated remote command execution has been identified in certain Hikvision Wireless Access Point models. This issue arises from inadequate input validation, which enables attackers with valid credentials to send crafted packets containing malicious commands to the affected devices, resulting in arbitrary command execution.
Exploitation of this vulnerability allows for authenticated remote command execution on the affected access points.
Users can download the fixed version from the Hikvision official website. The specific patched version is V1.1.6300 build250331 (R2263).
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.