CVE-2021-36260: presente nel catalogo CISA KEV

CVE-2021-36260 · CVSS 9.8 CRITICAL · EPSS 99.9% · KEV 2022-01-10

A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability to launch a command injection attack by sending some messages with malicious commands.

CVE-2021-36260 viene sfruttato?

Quali prodotti e versioni sono interessati?

Esiste una patch?

Nessun identificativo di patch registrato qui.

Cosa ha pubblicato PlainSec su CVE-2021-36260

Fonti primarie

Cosa questa scheda non dice

KEV ed EPSS vengono ricontrollati ogni giorno. Scheda aggiornata il 2026-10-08.