Global Security Crisis as 80,000 Hikvision Surveillance Cameras Remain Exposed to Critical Vulnerability Nearly a Year After Patch Release

The landscape of global cybersecurity is currently facing a significant and persistent threat as new research reveals that more than 80,000 Hikvision surveillance cameras remain unpatched against a critical command injection vulnerability. This flaw, which was first disclosed and addressed by the manufacturer nearly eleven months ago, continues to leave thousands of organizations across the globe susceptible to remote exploitation. Despite the availability of security updates, the sheer volume of exposed devices underscores a systemic failure in the maintenance of Internet of Things (IoT) infrastructure and highlights the growing gap between the discovery of vulnerabilities and the implementation of defensive measures.
The vulnerability, tracked as CVE-2021-36260, was assigned a critical severity rating of 9.8 out of 10 by the National Institute of Standards and Technology (NIST). This rating reflects the ease with which an attacker can exploit the flaw to gain full control over the affected device without requiring any user interaction or authentication. For a company like Hikvision—officially known as Hangzhou Hikvision Digital Technology, a Chinese state-owned entity—the stakes are particularly high. As one of the world’s largest suppliers of video surveillance equipment, their hardware is integrated into the security frameworks of government buildings, corporate offices, and sensitive infrastructure in over 100 countries.
The Technical Nature of CVE-2021-36260
To understand the gravity of the situation, one must look at the mechanics of the vulnerability. CVE-2021-36260 is a command injection flaw found in the web server component of various Hikvision products. Command injection occurs when an application passes unsafe user-supplied data (such as forms, cookies, or HTTP headers) to a system shell. In this specific case, an attacker can send a specially crafted message to the vulnerable device’s web interface, allowing them to execute arbitrary commands with the highest level of privileges.
Once an attacker gains this level of access, the camera is no longer a security tool but a liability. The malicious actor can intercept video feeds, disable recording, or, more dangerously, use the camera as a "beachhead" or pivot point to launch further attacks within the internal network. Because surveillance cameras are often connected to the same network as sensitive servers and workstations, they provide an ideal entry point for lateral movement, data exfiltration, and the deployment of ransomware.
Chronology of a Prolonged Exposure
The timeline of CVE-2021-36260 illustrates a troubling trend in the IoT industry where the "long tail" of unpatched devices remains a threat for years. The vulnerability was first identified in the late summer of 2021 by a security researcher known as "Watchful_IP." Recognizing the potential for widespread damage, the researcher followed responsible disclosure protocols, notifying Hikvision of the flaw.
In September 2021, Hikvision acknowledged the issue and released a series of firmware updates designed to close the hole. At the time, the company urged all users to update their devices immediately. However, as the months progressed, the rate of patching slowed significantly. By early 2022, security firms began noticing that tens of thousands of devices were still running outdated firmware.
In August 2022, a comprehensive report from the cybersecurity firm Cyfirma confirmed the worst-case scenario: over 80,000 cameras were still accessible via the public internet and remained vulnerable to the year-old exploit. This research indicated that the exposure was not limited to a specific region but was a global phenomenon, with significant clusters of vulnerable devices found in the United States, the United Kingdom, Brazil, and across Southeast Asia.
Threat Actors and Dark Web Activity
The persistence of this vulnerability has not escaped the notice of cybercriminals. Research into Russian-speaking dark web forums has revealed multiple instances of hackers collaborating to exploit Hikvision devices. These forums serve as marketplaces where leaked credentials and "bot" access are sold to the highest bidder. In many cases, hackers are not just looking for video feeds; they are building botnets.
Botnets comprised of IoT devices, such as the infamous Mirai botnet, are frequently used to launch massive Distributed Denial of Service (DDoS) attacks that can take down major websites and internet service providers. The processing power of 80,000 cameras, if harnessed by a single actor, would represent a formidable weapon in the digital underground.
Beyond opportunistic cybercriminals, state-sponsored threat groups are also a primary concern. Cyfirma’s report highlighted that groups such as APT41 (also known as MISSION2025) and APT10, both of which have been linked by Western intelligence to Chinese interests, possess the capability to exploit these vulnerabilities for geopolitical motives. Similarly, Russian-affiliated threat actors have shown an increasing interest in utilizing IoT vulnerabilities to facilitate espionage or disruptive operations against foreign entities.
The Geopolitical Context and National Security Risks
The widespread use of Hikvision technology has long been a point of contention in international relations. In 2019, the U.S. Federal Communications Commission (FCC) labeled Hikvision as an "unacceptable risk to U.S. national security." This was followed by the Secure Equipment Act of 2021, which effectively banned the licensing of new equipment from Hikvision and several other Chinese telecommunications firms within the United States.
The concerns are twofold: first, the potential for "backdoors" that could be used by the Chinese state for espionage; and second, the inherent security weaknesses in the hardware that make them easy targets for any malicious actor. The fact that 80,000 devices remain unpatched globally—including many within the borders of countries that have flagged the company as a risk—highlights a significant gap between policy and practice. Many organizations continue to use legacy Hikvision equipment because of its affordability and high performance, often ignoring the long-term security maintenance required to keep such devices safe.
Why IoT Devices Remain Unsecured
The failure to patch 80,000 devices is not merely a matter of administrative oversight; it is a symptom of the unique challenges inherent in IoT security. David Maynor, senior director of threat intelligence at Cybrary, notes that Hikvision’s products have historically suffered from systemic vulnerabilities, including the use of easily guessable default credentials.
"There is no good way to perform forensics or verify that an attacker has been excised once a device is compromised," Maynor stated. This lack of visibility makes it nearly impossible for an IT manager to know if their camera has been turned into a spy tool or a botnet node. Furthermore, Maynor observed that there has been little evidence of a shift in Hikvision’s internal development cycles to prioritize "security by design."
Paul Bischoff, a privacy advocate with Comparitech, points out that the user experience for IoT devices is fundamentally different from that of smartphones or PCs. "Updates are not automatic; users need to manually download and install them, and many users might never get the message," Bischoff explained. Unlike a modern operating system that prompts the user with a notification or installs updates during a reboot, many surveillance cameras require the user to log into a web interface, check for the correct firmware version on a manufacturer’s website, and manually upload the file. For many small business owners or residential users, this process is too complex or simply forgotten.
The Role of Search Engines in Exploitation
The ease with which attackers can find these 80,000 vulnerable cameras is facilitated by specialized search engines like Shodan and Censys. These tools crawl the internet specifically looking for connected devices, indexing their IP addresses, open ports, and firmware versions. A simple query on Shodan can reveal thousands of Hikvision cameras that are currently online and broadcasting their status.
When combined with the fact that many users never change the default "out-of-the-box" passwords, these cameras become low-hanging fruit for even novice hackers. The "lazy" approach to security—failing to change passwords and failing to apply patches—creates a perfect storm for exploitation.
Implications and Necessary Actions
The continued exposure of tens of thousands of surveillance cameras serves as a stark reminder of the "technical debt" associated with the rapid expansion of the Internet of Things. As more devices are connected to the web, the surface area for cyberattacks grows exponentially. The implications of CVE-2021-36260 extend beyond the privacy of a single video feed; they touch upon national security, corporate espionage, and the stability of the global internet.
To mitigate these risks, cybersecurity experts recommend several immediate steps for organizations utilizing Hikvision or similar IoT equipment:
- Immediate Firmware Audit: Organizations must inventory all connected cameras and verify that they are running the latest firmware. Any device that cannot be updated should be considered end-of-life and replaced.
- Network Segmentation: Surveillance systems should never be placed on the same network as sensitive corporate data. By using Virtual Local Area Networks (VLANs) and strict firewall rules, organizations can ensure that a compromised camera cannot be used to pivot to other systems.
- Credential Management: Default passwords must be changed immediately upon installation. Where possible, complex passwords and multi-factor authentication should be employed.
- Disabling Unnecessary Services: Features such as Universal Plug and Play (UPnP) and remote management interfaces should be disabled if they are not strictly necessary for operation.
The story of the 80,000 unpatched Hikvision cameras is a cautionary tale for the digital age. It demonstrates that in the world of cybersecurity, a patch is only effective if it is applied. Until the industry moves toward more automated, transparent, and user-friendly security updates, the "unpatched masses" of the IoT world will continue to provide a playground for hackers and a headache for defenders. The window of opportunity for these 80,000 devices has been open for nearly a year; for many, the question is no longer if they will be compromised, but when.







