TROYANOSYVIRUS
Back to CVEs

CVE-2025-66176

HIGH
8.8

Description

There is a Stack overflow Vulnerability in the device Search and Discovery feature of Hikvision Access Control Products. If exploited, an attacker on the same local area network (LAN) could cause the device to malfunction by sending specially crafted packets to an unpatched device.

CVE Details

CVSS v3.1 Score8.8
SeverityHIGH
CVSS VectorCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack VectorADJACENT_NETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published1/13/2026
Last Modified3/18/2026
Sourcenvd
Honeypot Sightings0

Affected Products

hikvision:ds-k1t105ahikvision:ds-k1t105a_firmwarehikvision:ds-k1t201ahikvision:ds-k1t201a_firmwarehikvision:ds-k1t320hikvision:ds-k1t320_firmwarehikvision:ds-k1t321hikvision:ds-k1t321_firmwarehikvision:ds-k1t323hikvision:ds-k1t323_firmwarehikvision:ds-k1t331hikvision:ds-k1t331_firmwarehikvision:ds-k1t341ahikvision:ds-k1t341a_firmwarehikvision:ds-k1t341bhikvision:ds-k1t341b_firmwarehikvision:ds-k1t341chikvision:ds-k1t341c_firmwarehikvision:ds-k1t342hikvision:ds-k1t342_firmwarehikvision:ds-k1t343hikvision:ds-k1t343_firmwarehikvision:ds-k1t344hikvision:ds-k1t344_firmwarehikvision:ds-k1t510hikvision:ds-k1t510_firmwarehikvision:ds-k1t670hikvision:ds-k1t670_firmwarehikvision:ds-k1t671hikvision:ds-k1t671_firmwarehikvision:ds-k1t672hikvision:ds-k1t672_firmwarehikvision:ds-k1t673hikvision:ds-k1t673_firmwarehikvision:ds-k1t680hikvision:ds-k1t680_firmwarehikvision:ds-k1t6qt-f43hikvision:ds-k1t6qt-f43_firmwarehikvision:ds-k1t6qt-f72hikvision:ds-k1t6qt-f72_firmwarehikvision:ds-k1t8003hikvision:ds-k1t8003_firmwarehikvision:ds-k1t8005hikvision:ds-k1t8005_firmwarehikvision:ds-k1t804ahikvision:ds-k1t804a_firmwarehikvision:ds-k1t804bhikvision:ds-k1t804b_firmwarehikvision:ds-k1t808hikvision:ds-k1t808_firmwarehikvision:ds-k1t981hikvision:ds-k1t981_firmwarehikvision:ds-k5033hikvision:ds-k5033_firmwarehikvision:ds-k5671hikvision:ds-k5671_firmware

Weaknesses (CWE)

CWE-121

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.