Cybercriminals Are Selling Access to Chinese Surveillance Cameras
A critical command injection vulnerability (CVE-2021-36260) affecting Hikvision surveillance cameras remains unpatched in over 80,000 devices worldwide nearly a year after disclosure. The vulnerability has a critical severity rating of 9.8 and allows remote command injection. Despite the severity, many devices remain exposed due to challenges in patching IoT devices and use of default credentials. Cybercriminals are actively selling access to these vulnerable cameras on dark web forums. The full extent of exploitation is unclear, but threat actors including Chinese and Russian groups could potentially leverage this flaw.
AI Analysis
Technical Summary
CVE-2021-36260 is a critical command injection vulnerability in Hikvision surveillance cameras disclosed in late 2021. It received a CVSS score of 9.8, indicating critical severity. The flaw allows remote attackers to execute arbitrary commands on affected devices. Despite the availability of patches, over 80,000 devices remain vulnerable globally due to difficulties in patch deployment and poor security practices such as default passwords. Cybercriminals have been observed selling access to these compromised cameras on Russian dark web forums. The vulnerability affects a broad range of Hikvision cameras used worldwide, including in the United States. The vendor has not demonstrated significant improvements in security posture or update mechanisms for these IoT devices.
Potential Impact
The vulnerability enables remote command injection on affected Hikvision cameras, potentially allowing attackers to take control of the devices. This exposure risks unauthorized surveillance, privacy breaches, and could serve as a foothold for further network compromise. The large number of unpatched devices increases the attack surface and facilitates cybercriminal activity, including the sale of access credentials. Although no confirmed active exploitation is reported, the presence of threat actors discussing and trading access indicates a credible threat. The impact is significant given the critical severity and widespread deployment of these devices.
Mitigation Recommendations
Patch status is not yet confirmed from the provided data; users should consult Hikvision's official advisories for current remediation guidance. Users are strongly advised to apply any available firmware updates addressing CVE-2021-36260. Additionally, changing default passwords and disabling unnecessary remote access features can reduce exposure. Due to the challenges in automatic updates for IoT devices, organizations should verify device security configurations and monitor for unauthorized access. No vendor advisory content was provided to confirm patch availability or official fixes.
Cybercriminals Are Selling Access to Chinese Surveillance Cameras
Description
A critical command injection vulnerability (CVE-2021-36260) affecting Hikvision surveillance cameras remains unpatched in over 80,000 devices worldwide nearly a year after disclosure. The vulnerability has a critical severity rating of 9.8 and allows remote command injection. Despite the severity, many devices remain exposed due to challenges in patching IoT devices and use of default credentials. Cybercriminals are actively selling access to these vulnerable cameras on dark web forums. The full extent of exploitation is unclear, but threat actors including Chinese and Russian groups could potentially leverage this flaw.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2021-36260 is a critical command injection vulnerability in Hikvision surveillance cameras disclosed in late 2021. It received a CVSS score of 9.8, indicating critical severity. The flaw allows remote attackers to execute arbitrary commands on affected devices. Despite the availability of patches, over 80,000 devices remain vulnerable globally due to difficulties in patch deployment and poor security practices such as default passwords. Cybercriminals have been observed selling access to these compromised cameras on Russian dark web forums. The vulnerability affects a broad range of Hikvision cameras used worldwide, including in the United States. The vendor has not demonstrated significant improvements in security posture or update mechanisms for these IoT devices.
Potential Impact
The vulnerability enables remote command injection on affected Hikvision cameras, potentially allowing attackers to take control of the devices. This exposure risks unauthorized surveillance, privacy breaches, and could serve as a foothold for further network compromise. The large number of unpatched devices increases the attack surface and facilitates cybercriminal activity, including the sale of access credentials. Although no confirmed active exploitation is reported, the presence of threat actors discussing and trading access indicates a credible threat. The impact is significant given the critical severity and widespread deployment of these devices.
Defensive Guidance
Patch status is not yet confirmed from the provided data; users should consult Hikvision's official advisories for current remediation guidance. Users are strongly advised to apply any available firmware updates addressing CVE-2021-36260. Additionally, changing default passwords and disabling unnecessary remote access features can reduce exposure. Due to the challenges in automatic updates for IoT devices, organizations should verify device security configurations and monitor for unauthorized access. No vendor advisory content was provided to confirm patch availability or official fixes.
Technical Details
- Classification
- {"confidence":0.3,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://threatpost.com/cybercriminals-are-selling-access-to-chinese-surveillance-cameras/180478/","fetched":true,"fetchedAt":"2026-08-04T12:41:22.400Z","wordCount":790}
Threat ID: 6a71ddf3bf8831d539cc9787
Added to database: 08/04/2026, 12:41:23 UTC
Last enriched: 08/04/2026, 12:42:40 UTC
Last updated: 09/14/2026, 22:25:33 UTC
Views: 49
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.