CVE-2026-61391
Deferred Deferred - Pending Action

Stack-Based Buffer Overflow in Hikvision Camera Firmware

Vulnerability report for CVE-2026-61391, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-22

Last updated on: 2026-07-22

Assigner: Hangzhou Hikvision Digital Technology Co., Ltd.

Description

There is a stack-based buffer overflow vulnerability in some Hikvision cameras, which may allow authenticated attackers to cause device malfunction by sending specially crafted packets.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-22
Last Modified
2026-07-22
Generated
2026-08-11
AI Q&A
2026-07-22
EPSS Evaluated
2026-08-10
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hikvision camera *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-121 A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a stack-based buffer overflow in certain Hikvision cameras. It allows authenticated attackers to send specially crafted network packets that can cause the device to malfunction by overwriting parts of the device's memory.

Impact Analysis

An attacker could exploit this to cause the camera to crash or behave unpredictably. This may lead to loss of surveillance, unauthorized access to camera feeds, or potential further compromise of connected systems if the attacker gains control.

Compliance Impact

This vulnerability could impact compliance by potentially exposing sensitive data if camera feeds are accessed or altered. Organizations may fail to meet requirements for data protection and privacy if such breaches occur due to inadequate security measures.

Mitigation Strategies

Update Hikvision camera firmware to the latest version to patch the stack-based buffer overflow vulnerability. Restrict network access to cameras by using firewalls and only allow trusted IP addresses. Monitor network traffic for unusual packets targeting camera ports.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-61391. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart