Tens of thousands of cameras have failed to patch a critical, 11-month-old CVE, leaving thousands of organizations exposed.

A critical cybersecurity vulnerability, first disclosed nearly a year ago, continues to leave tens of thousands of Hikvision surveillance cameras globally exposed to potential compromise. New research indicates that over 80,000 of these devices remain unpatched, creating a significant and persistent risk for organizations that rely on them for security and surveillance. This widespread vulnerability, identified as CVE-2021-36260, allows for command injection, a severe flaw that could enable malicious actors to gain unauthorized control over the affected cameras.
Hikvision, a prominent Chinese state-owned manufacturer of video surveillance equipment, supplies its products to over 100 countries. Despite its global reach, the company has faced scrutiny regarding its security practices. Notably, in 2019, the U.S. Federal Communications Commission (FCC) designated Hikvision as "an unacceptable risk to U.S. national security," a designation that underscores the potential geopolitical implications of compromised surveillance technology.
The command injection flaw, CVE-2021-36260, was publicly disclosed in the fall of last year. It was subsequently assigned a critical severity rating of 9.8 out of 10 by the National Institute of Standards and Technology (NIST), a testament to its potential for exploitation. Despite this alarming assessment and the significant timeframe since its discovery, a substantial number of Hikvision cameras continue to operate without the necessary security updates.
The persistence of this vulnerability has not gone unnoticed by cybercriminals. Researchers have observed multiple instances of threat actors actively discussing and collaborating on exploiting these Hikvision cameras, particularly within Russian dark web forums. These discussions often revolve around the sale of leaked credentials, which can be used in conjunction with the command injection flaw to gain deeper access and control over compromised devices.
While the full extent of the damage already inflicted by this vulnerability remains unclear, the authors of the latest research report have speculated on the potential perpetrators and their motives. They suggest that Chinese threat groups, such as MISSION2025/APT41 and APT10 and their affiliates, as well as unidentified Russian threat actor groups, could be leveraging these vulnerabilities. The motivations behind such attacks could range from espionage and intelligence gathering to disruptive activities, potentially driven by geo-political considerations. The widespread deployment of these cameras in critical infrastructure, government facilities, and private enterprises amplifies the potential impact of a successful exploitation.
The Pervasive Challenge of IoT Security
The ongoing exposure of Hikvision cameras highlights a broader, systemic challenge within the Internet of Things (IoT) sector. While it might be tempting to attribute the lack of patching to user negligence or laziness, the reality is often more complex and deeply rooted in the inherent nature of IoT device management and security.
David Maynor, senior director of threat intelligence at Cybrary, points to several systemic issues contributing to the prolonged vulnerability of Hikvision cameras. He notes that the products have historically contained easily exploitable vulnerabilities, or in some cases, default credentials that are never changed. Furthermore, the forensic capabilities for detecting and removing attackers from compromised IoT devices are often inadequate. Maynor also observes a lack of visible improvement in Hikvision’s security development lifecycle, suggesting that the underlying issues may not be systematically addressed.
Paul Bischoff, a privacy advocate with Comparitech, echoes these sentiments, emphasizing that securing IoT devices presents distinct challenges compared to more conventional software applications. "IoT devices like cameras aren’t always as easy or straightforward to secure as an app on your phone," Bischoff stated in an email. "Updates are not automatic; users need to manually download and install them, and many users might never get the message." He further explains that IoT devices often lack the user-friendly notifications and automatic update mechanisms common on smartphones. Users may not receive any indication that their devices are unsecured or outdated, unlike a smartphone that typically alerts users to available updates and prompts for installation.
This lack of user awareness, coupled with the technical complexities of updating embedded systems, creates a fertile ground for exploitation. Cybercriminals can efficiently scan the internet for vulnerable devices using specialized search engines like Shodan and Censys. The problem is exacerbated by common user practices, such as failing to change default passwords. As Bischoff highlighted, Hikvision cameras, like many other IoT devices, are often shipped with a limited set of predetermined passwords, and many users neglect to alter these factory-set credentials, inadvertently providing attackers with a significant head start.
The confluence of weak inherent security, insufficient visibility for end-users, and a lack of proactive oversight from manufacturers and users alike raises serious questions about the future security posture of these tens of thousands of compromised cameras. It remains uncertain when, or even if, these devices will be brought to a secure state, leaving a significant attack surface open to malicious actors.
A Timeline of Vulnerability and Exploitation
The story of CVE-2021-36260 is a stark illustration of the challenges in managing vulnerabilities in widely deployed IoT devices. Understanding the timeline of its disclosure, patching efforts, and subsequent exploitation provides crucial context for the current situation.
Early 2021: It is highly probable that the command injection vulnerability existed within Hikvision camera firmware for an extended period prior to its public disclosure. Identifying the exact initial emergence of the flaw is difficult without internal company data. However, the nature of command injection vulnerabilities often means they can be present for years if not actively sought out and remediated.
Mid-2021 (exact date of discovery by researchers unknown): Security researchers, likely through proactive threat hunting or bug bounty programs, discover the critical command injection vulnerability, CVE-2021-36260, within Hikvision surveillance cameras. This discovery marks the first step towards addressing the flaw.
Late Summer/Early Fall 2021: The vulnerability is officially disclosed to the public. This typically involves reporting the vulnerability to the vendor (Hikvision) for a period of responsible disclosure, allowing them time to develop and release patches. Following this, the vulnerability is published in public databases like NIST’s National Vulnerability Database (NVD). The critical rating of 9.8/10 is assigned, signaling its extreme severity.
October 2021 – Present: Hikvision begins to release firmware updates intended to patch CVE-2021-36260. However, the adoption rate of these patches proves to be extremely slow across the global user base. Factors contributing to this include the manual nature of firmware updates for many IoT devices, lack of user awareness, and potential technical challenges in applying updates in diverse deployment environments.
Late 2021 – Early 2022: As unpatched devices proliferate, threat actors begin to actively seek out and exploit the vulnerability. Researchers observe discussions on dark web forums, indicating a growing interest among cybercriminals in leveraging CVE-2021-36260 for malicious purposes. This includes the sale of credentials that can be used in conjunction with the exploit.
Mid-2022 (Current Research Findings): New research emerges, quantifying the scale of the problem. It reveals that over 80,000 Hikvision cameras worldwide remain vulnerable, highlighting the significant gap between the disclosure of the vulnerability and the implementation of effective mitigation measures. The research also reiterates the ongoing interest of threat actors in exploiting these devices.
This protracted timeline underscores a critical failure in the ecosystem of IoT security: the disconnect between vulnerability discovery and effective remediation across a vast and diverse installed base.
Supporting Data and Broader Context
The sheer volume of unpatched Hikvision cameras is not an isolated incident but rather symptomatic of a larger trend in the IoT security landscape. The global market for video surveillance cameras is substantial and rapidly expanding. According to Statista, the global video surveillance market size was valued at approximately USD 53.1 billion in 2021 and is projected to reach USD 138.2 billion by 2028, exhibiting a compound annual growth rate (CAGR) of 14.5%. This growth signifies an ever-increasing number of connected devices, each representing a potential entry point for cyber threats if not adequately secured.
Hikvision, as one of the largest manufacturers in this sector, holds a significant market share. While exact figures for the number of Hikvision cameras in active use globally are difficult to ascertain publicly, the research indicating over 80,000 unpatched devices suggests a substantial installed base. This number, representing a fraction of their total deployments, still poses a considerable risk.
The vulnerability CVE-2021-36260 allows for command injection, a type of exploit where an attacker can execute arbitrary commands on the target system. In the context of a surveillance camera, this could grant an attacker the ability to:
- View Live Feeds: Access real-time video streams, compromising privacy and potentially enabling industrial espionage or personal stalking.
- Access Stored Footage: Retrieve recorded video evidence, which could be used for blackmail or to gain insights into sensitive operations.
- Manipulate Camera Settings: Alter recording schedules, disable motion detection, or even redirect camera views, rendering them ineffective for their intended security purpose.
- Use as a Pivot Point: Compromise the camera to gain access to the internal network it is connected to. This can be a stepping stone for more sophisticated attacks targeting other critical systems within an organization.
- Incorporate into Botnets: The camera could be enslaved and used as part of a distributed denial-of-service (DDoS) attack or for other nefarious activities, further obfuscating the origin of malicious traffic.
The implications of these potential actions are far-reaching. For businesses, compromised cameras could lead to data breaches, intellectual property theft, reputational damage, and operational disruptions. For government entities, the risk extends to national security concerns, as critical infrastructure could be monitored or disrupted.
The concern is amplified by the geopolitical context surrounding Hikvision. The company’s state-owned status and the FCC’s designation of its products as an "unacceptable risk" have led some governments and organizations to restrict or ban the use of Hikvision equipment. However, the sheer volume of existing installations, particularly in regions with less stringent import controls or where cost is a primary driver, means that a significant number of these devices remain in operation and vulnerable.
Official Responses and Industry Reactions
As of the latest reporting, there has been no broad, official public statement from Hikvision directly addressing the ongoing prevalence of unpatched CVE-2021-36260 vulnerabilities. Typically, after a critical vulnerability is disclosed, manufacturers issue security advisories and release updated firmware. Hikvision has indeed released firmware updates to address CVE-2021-36260. However, the lack of widespread adoption of these patches, as highlighted by the research, indicates a significant gap in the communication and implementation chain.
The cybersecurity industry, however, has been vocal about the implications. Security researchers and threat intelligence firms consistently highlight the importance of timely patching for IoT devices. The findings from the recent research serve as a stark reminder to organizations about the critical need for robust patch management strategies for all connected devices, not just traditional IT infrastructure.
The U.S. government, through agencies like the Cybersecurity and Infrastructure Security Agency (CISA), has repeatedly issued warnings and guidance regarding the exploitation of IoT vulnerabilities. While CISA may not issue specific alerts for every unpatched device from a particular vendor unless it reaches a critical threshold of immediate national threat, the general advisory to secure IoT devices and implement regular patching remains a cornerstone of their cybersecurity recommendations. The presence of over 80,000 unpatched Hikvision cameras would likely fall under CISA’s general purview for entities to take immediate action.
The situation also draws attention to the responsibilities of device manufacturers. Experts like David Maynor suggest that manufacturers need to move beyond simply releasing patches. They should also focus on:
- Simplifying the Update Process: Implementing automatic updates or providing clear, accessible, and user-friendly methods for manual updates.
- Enhancing Device Forensics: Enabling easier detection of compromises and facilitating the removal of malicious actors.
- Improving Development Security: Integrating security into the entire product development lifecycle to prevent such systemic vulnerabilities from occurring in the first place.
Broader Impact and Implications
The continued exposure of tens of thousands of Hikvision cameras due to an unpatched, critical vulnerability has far-reaching implications that extend beyond the immediate threat of compromise. This situation serves as a potent case study for the inherent risks associated with the rapidly expanding Internet of Things (IoT) ecosystem and highlights critical areas requiring immediate attention from manufacturers, users, and regulators alike.
Amplified Cyber Threat Landscape: The existence of a large number of vulnerable devices creates a significant and persistent attack surface. This not only poses a direct risk to the organizations deploying these cameras but also contributes to the overall global threat landscape. Compromised cameras can be weaponized for large-scale cyberattacks, including botnet operations and distributed denial-of-service (DDoS) attacks, impacting internet infrastructure and other online services. The potential for these devices to be used as entry points into corporate or governmental networks also increases the risk of sophisticated, multi-stage attacks.
Erosion of Trust in Surveillance Technology: The widespread vulnerability of surveillance equipment, particularly from a prominent manufacturer, can erode public and organizational trust in the very technology designed to enhance security. This distrust can lead to hesitations in adopting new security technologies and can fuel debates about the inherent security risks of interconnected devices. For organizations that have invested heavily in Hikvision systems, the ongoing vulnerability can lead to significant financial losses, not only from potential breaches but also from the cost of replacing or fortifying these systems.
Geopolitical Security Concerns: Given Hikvision’s state-owned nature and the prior U.S. national security concerns, the continued vulnerability of its devices takes on an added layer of geopolitical significance. The potential for foreign state-sponsored actors to exploit these cameras for intelligence gathering or disruptive purposes represents a tangible national security threat. This situation underscores the complex interplay between technology, global trade, and national security, potentially leading to increased trade restrictions and scrutiny of technology supply chains.
Regulatory and Compliance Challenges: The incident highlights the ongoing challenges in regulating and enforcing cybersecurity standards for IoT devices. While some regions have implemented regulations, the global nature of manufacturing and deployment makes comprehensive oversight difficult. This situation may prompt increased calls for stricter regulations on IoT device security, including mandatory vulnerability disclosure timelines, robust patch management requirements, and clearer accountability for manufacturers. Organizations are also facing increasing pressure to demonstrate compliance with evolving cybersecurity standards, which may require them to conduct thorough audits of their IoT device inventories and patch status.
The Imperative for Proactive Security Posture: For organizations, this incident is a wake-up call. It emphasizes the critical need to move beyond a reactive approach to cybersecurity and adopt a proactive stance. This includes:
- Comprehensive Asset Inventory: Maintaining an accurate and up-to-date inventory of all connected devices, including IoT devices.
- Vulnerability Management Programs: Implementing robust processes for identifying, assessing, and prioritizing vulnerabilities across all deployed assets.
- Patch Management Policies: Establishing clear policies and procedures for timely patching of all devices, with a particular focus on critical vulnerabilities.
- Security by Design: When procuring new IoT devices, prioritizing manufacturers with a proven track record of security and a commitment to ongoing support and updates.
- Network Segmentation: Isolating IoT devices on separate network segments to limit the potential impact of a compromise.
- Regular Security Audits: Conducting periodic security assessments and penetration tests to identify and address potential weaknesses.
The ongoing exposure of these Hikvision cameras, nearly a year after the critical vulnerability was disclosed, serves as a stark reminder that the fight against cyber threats is an ongoing battle. Without a concerted effort from manufacturers to improve product security and from users to diligently maintain their deployed devices, the IoT landscape will continue to present significant and avoidable risks. The question is not if these vulnerable devices will be exploited further, but rather when and to what extent the consequences will be felt.







