CVE-2026-85544
Deferred Deferred - Pending Action

Improper Encryption Configuration in Hikvision Intercom Products

Vulnerability report for CVE-2026-85544, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-10

Last updated on: 2026-09-18

Assigner: Hangzhou Hikvision Digital Technology Co., Ltd.

Description

There is an Improper Encryption Configuration Vulnerability in some Hikvision Intercom Products. This could allow attackers to forge M1 cards.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-10
Last Modified
2026-09-18
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-29
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hikvision intercom_products *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-798 The product contains hard-coded credentials, such as a password or cryptographic key.
CWE-1310 Missing an ability to patch ROM code may leave a System or System-on-Chip (SoC) in a vulnerable state.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves an improper encryption configuration in certain Hikvision Intercom Products. It allows attackers to forge M1 cards, which are likely used for authentication or access control.

Impact Analysis

Attackers could exploit this to create fake M1 cards, potentially gaining unauthorized access to intercom systems. This may lead to physical security breaches or unauthorized entry into restricted areas.

Compliance Impact

This vulnerability involves improper encryption configuration in Hikvision Intercom Products, allowing attackers to forge M1 cards. Such weaknesses could potentially expose sensitive data, impacting compliance with standards like GDPR (data protection) and HIPAA (healthcare data privacy) by increasing the risk of unauthorized access or data breaches.

Mitigation Strategies

Immediately update Hikvision Intercom Products to the latest firmware version provided by Hikvision to address the improper encryption configuration. Disable M1 card functionality if not required and restrict network access to the intercom system to trusted networks only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85544. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart