TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2025-66173

MEDIUM
6.2

Beschreibung

There is a privilege escalation vulnerability in some Hikvision DVR products. Due to the improper implementation of authentication for the serial port, an attacker with physical access could exploit this vulnerability by connecting to the affected products and gaining access to an unrestricted shell environment.

CVE Details

CVSS v3.1 Bewertung6.2
SchweregradMEDIUM
CVSS VektorCVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorPHYSICAL
KomplexitatLOW
Erforderliche PrivilegienHIGH
BenutzerinteraktionNONE
Veroffentlicht12/19/2025
Zuletzt geandert12/23/2025
Quellenvd
Honeypot-Sichtungen0

Betroffene Produkte

hikvision:ds-7104hghi-f1hikvision:ds-7104hghi-f1_firmwarehikvision:ds-7204hghi-f1hikvision:ds-7204hghi-f1_firmware

Schwachen (CWE)

CWE-269

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.