{"id":9834,"date":"2026-01-13T10:04:09","date_gmt":"2026-01-13T10:04:09","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/01\/13\/multiple-hikvision-vulnerabilities-let-attackers-cause-device-malfunction-using-crafted-packets\/"},"modified":"2026-01-13T10:04:09","modified_gmt":"2026-01-13T10:04:09","slug":"multiple-hikvision-vulnerabilities-let-attackers-cause-device-malfunction-using-crafted-packets","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/01\/13\/multiple-hikvision-vulnerabilities-let-attackers-cause-device-malfunction-using-crafted-packets\/","title":{"rendered":"Multiple Hikvision Vulnerabilities Let Attackers Cause Device Malfunction Using Crafted Packets"},"content":{"rendered":"<p>    Multiple Hikvision Vulnerabilities Let Attackers Cause Device Malfunction Using Crafted Packets<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Hikvision, a leading provider of surveillance and access control systems, faces serious security risks from two newly disclosed stack overflow vulnerabilities.<\/p>\n<p>These flaws, tracked as CVE-2025-66176 and CVE-2025-66177, allow attackers on the same local area network (LAN) to trigger device malfunctions by sending specially crafted packets. Both carry a high CVSS v3.1 base score of 8.8, indicating significant potential impact without requiring authentication.<\/p>\n<p>Security researchers uncovered these issues in Hikvision\u2019s device Search and Discovery feature, a protocol used for network detection.<\/p>\n<p>Exploitation demands only adjacent network access, such as shared Wi-Fi or office LANs, making it a prime target for insiders or opportunistic hackers. An unpatched device could crash entirely, disrupting critical operations in surveillance setups.<\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th>CVE ID<\/th>\n<th>Affected Products<\/th>\n<th>CVSS v3.1 Base Score<\/th>\n<th>Description<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>CVE-2025-66176<\/td>\n<td>Partial Access Control Series Products<\/td>\n<td>8.8 (AV:A\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H)<\/td>\n<td>Stack overflow in Search and Discovery feature<\/td>\n<\/tr>\n<tr>\n<td>CVE-2025-66177<\/td>\n<td>Partial NVR, DVR, CVR, IPC Series Products<\/td>\n<td>8.8 (AV:A\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H)<\/td>\n<td>Stack overflow in Search and Discovery feature<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>The vector breakdown reveals low complexity: attackers need no privileges (PR:N) and no user interaction (UI:N), with high confidentiality, integrity, and availability impacts (C:H\/I:H\/A:H).<\/p>\n<p>CVE-2025-66176 was reported by a Cisco Talos Team member, while CVE-2025-66177 came from independent researchers Angel Lozano Alcazar and Pedro Guillen Nu\u00f1ez. Their disclosures underscore ongoing scrutiny of IoT and surveillance gear, where stack overflows have repeatedly enabled denial-of-service attacks.<\/p>\n<p>Hikvision <a href=\"https:\/\/www.hikvision.com\/en\/support\/cybersecurity\/security-advisory\/buffer-overflow-vulnerabilities-in-some-hikvision-products\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">urges<\/a> immediate patching. Users can download firmware updates from the <a href=\"https:\/\/www.hikvision.com\/en\/support\/download\/firmware\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">official support page<\/a>. The company emphasizes network segmentation and disabling unused discovery features as interim mitigations.<\/p>\n<p>These flaws arrive amid heightened concerns over video surveillance security. Last year saw similar Hikvision advisories, prompting CISA alerts on supply chain risks. Organizations relying on these devices, from smart buildings to public safety, should prioritize scans using tools like Nmap for exposed services.<\/p>\n<p>Experts warn that unpatched systems could lead to broader incidents, such as surveillance blackouts during emergencies. \u201cLAN-adjacent attacks lower the bar for disruption,\u201d noted a Talos spokesperson. As threats evolve, vendors must accelerate zero-trust implementations in embedded systems.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/multiple-hikvision-lan-vulnerabilities\/\">Multiple Hikvision Vulnerabilities Let Attackers Cause Device Malfunction Using Crafted Packets<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/multiple-hikvision-lan-vulnerabilities\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Multiple Hikvision Vulnerabilities Let Attackers Cause Device Malfunction Using Crafted Packets Hikvision, a leading provider of surveillance and access control systems, faces serious security risks from two newly disclosed stack overflow vulnerabilities. These flaws, tracked as CVE-2025-66176 and CVE-2025-66177, allow attackers on the same local area network (LAN) to trigger device malfunctions by sending specially [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,131,648],"tags":[130],"class_list":["post-9834","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9834"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9834"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9834\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9834"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9834"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9834"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}