Hikvision Status Endpoint Makes Cameras Easier to Find

A simple status endpoint gives attackers a cheap way to separate real Hikvision targets from noise before they try passwords. The standard mistake is to treat this as harmless recon; in practice, it lowers the cost of targeting internet-exposed cameras and any ISAPI integration that should not have been reachable in the first place. SANS ISC saw new internet-wide scans this weekend against /ISAPI/System/status on Hikvision’s OPEN Intelligent Security API. The endpoint returns different responses when ISAPI is present, so a scanner can inventory devices and narrow brute-force attempts without spraying every camera blindly. There is no confirmed exploitation yet. The risk is that exposed management endpoints that answer differently to “exists” and “doesn’t exist” become efficient recon beacons, and the same pattern applies beyond Hikvision.

Part of the PlainSec briefing for 2026-07-19

Sources