← Back

CVE-2025-66173

nvd nist
Published: Dec 19, 2025Modified: Dec 23, 2025

JSON object

Loading...
6.2
Vector
CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.3 / Impact: 5.9
Source: hsrc@hikvision.com (Secondary)

Description

There is a privilege escalation vulnerability in some Hikvision DVR products. Due to the improper implementation of authentication for the serial port, an attacker with physical access could exploit this vulnerability by connecting to the affected products and gaining access to an unrestricted shell environment.

Affected (2)

2 products
Ds 7104hghi F1 Firmware
Ds 7204hghi F1 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 4.30.122_201107
Running on/withPlatform Versions
Hikvision
Ds 7104hghi F1
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 4.30.122_201107
Running on/withPlatform Versions
Hikvision
Ds 7204hghi F1
All versions

Timeline

No history available yet.