Hikvision DVR Privilege Escalation Vulnerability via Serial Port Authentication Flaw

Vulnerability

A privilege escalation vulnerability has been identified in certain Hikvision DVR models. This issue arises from improper authentication implementation for the serial port, allowing an attacker with physical access to connect to the affected devices and gain entry to an unrestricted shell environment.

Impact

Exploitation of this vulnerability allows for unauthorized privilege escalation, granting access to a shell environment with elevated rights on the affected device.

Remediation

Users can upgrade to version V4.30.123_251114 to address this vulnerability. This version is available for download from the Hikvision firmware repository.

Added: Dec 19, 2025, 7:24 AM
Updated: Dec 19, 2025, 7:24 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
3.3
remediation
7.7
relevance
1.5
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.