CVE-2026-85544
Deferred
Deferred - Pending Action
Improper Encryption Configuration in Hikvision Intercom Products
Vulnerability report for CVE-2026-85544, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-10
Last updated on: 2026-09-18
Assigner: Hangzhou Hikvision Digital Technology Co., Ltd.
Description
Description
There is an Improper Encryption Configuration Vulnerability in some Hikvision Intercom Products. This could allow attackers to forge M1 cards.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| hikvision | intercom_products | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-798 | The product contains hard-coded credentials, such as a password or cryptographic key. |
| CWE-1310 | Missing an ability to patch ROM code may leave a System or System-on-Chip (SoC) in a vulnerable state. |