Skip to main content

Cybercriminals Are Selling Access to Chinese Surveillance Cameras

0
Critical
News
Published: 08/25/2022 (08/25/2022, 18:47:15 UTC)
Source: Threatpost

Description

A critical command injection vulnerability (CVE-2021-36260) affecting Hikvision surveillance cameras remains unpatched in over 80,000 devices worldwide nearly a year after disclosure. The vulnerability has a critical severity rating of 9.8 and allows remote command injection. Despite the severity, many devices remain exposed due to challenges in patching IoT devices and use of default credentials. Cybercriminals are actively selling access to these vulnerable cameras on dark web forums. The full extent of exploitation is unclear, but threat actors including Chinese and Russian groups could potentially leverage this flaw.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/04/2026, 12:42:40 UTC

Technical Analysis

CVE-2021-36260 is a critical command injection vulnerability in Hikvision surveillance cameras disclosed in late 2021. It received a CVSS score of 9.8, indicating critical severity. The flaw allows remote attackers to execute arbitrary commands on affected devices. Despite the availability of patches, over 80,000 devices remain vulnerable globally due to difficulties in patch deployment and poor security practices such as default passwords. Cybercriminals have been observed selling access to these compromised cameras on Russian dark web forums. The vulnerability affects a broad range of Hikvision cameras used worldwide, including in the United States. The vendor has not demonstrated significant improvements in security posture or update mechanisms for these IoT devices.

Potential Impact

The vulnerability enables remote command injection on affected Hikvision cameras, potentially allowing attackers to take control of the devices. This exposure risks unauthorized surveillance, privacy breaches, and could serve as a foothold for further network compromise. The large number of unpatched devices increases the attack surface and facilitates cybercriminal activity, including the sale of access credentials. Although no confirmed active exploitation is reported, the presence of threat actors discussing and trading access indicates a credible threat. The impact is significant given the critical severity and widespread deployment of these devices.

Defensive Guidance

Patch status is not yet confirmed from the provided data; users should consult Hikvision's official advisories for current remediation guidance. Users are strongly advised to apply any available firmware updates addressing CVE-2021-36260. Additionally, changing default passwords and disabling unnecessary remote access features can reduce exposure. Due to the challenges in automatic updates for IoT devices, organizations should verify device security configurations and monitor for unauthorized access. No vendor advisory content was provided to confirm patch availability or official fixes.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.3,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://threatpost.com/cybercriminals-are-selling-access-to-chinese-surveillance-cameras/180478/","fetched":true,"fetchedAt":"2026-08-04T12:41:22.400Z","wordCount":790}

Threat ID: 6a71ddf3bf8831d539cc9787

Added to database: 08/04/2026, 12:41:23 UTC

Last enriched: 08/04/2026, 12:42:40 UTC

Last updated: 09/14/2026, 22:25:33 UTC

Views: 49

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses