Summary
CVE-2026-57600 is a high-severity information disclosure vulnerability affecting Hikvision DS-2CD, DS-2DE, DS-2DP, and DS-2TD Series IP cameras. Insufficient validation of input parameters in the device firmware allows unauthenticated remote attackers to retrieve partial sensitive data from affected devices over the network. Discovered by the Bitdefender IoT Security Team, the vulnerability carries a CVSS v3.1 base score of 7.5 (High).
Technical details
- Root cause: Insufficient validation of input parameters in the firmware’s network-facing interface, enabling malformed or crafted requests to bypass expected processing boundaries and return sensitive data.
- Trigger conditions: No authentication, no user interaction, and no special configuration required. The attack can be carried out by any network-reachable attacker against an internet-exposed device.
- Attack vector: Network-based (AV:N), low attack complexity (AC:L), no privileges required (PR:N), no user interaction (UI:N).
- Impact: Unauthenticated retrieval of partial sensitive data from affected camera firmware. The CVSS Confidentiality impact is rated High (C:H), indicating significant sensitive information is accessible to an attacker. Integrity and availability are not affected (I:N/A:N).
Affected software
- Hikvision DS-2CD Series IP cameras (affected firmware versions)
- Hikvision DS-2DE Series IP cameras (affected firmware versions)
- Hikvision DS-2DP Series IP cameras (affected firmware versions)
- Hikvision DS-2TD Series IP cameras (affected firmware versions)
Specific affected firmware version ranges and corresponding fixed firmware versions are detailed in Hikvision’s official security advisory (see References).
Severity
- CVSS v3.1 Base Score: 7.5 (High)
- Vector String:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Mitigation and recommended actions
- Immediate: Apply the firmware update for affected device models provided by Hikvision. Consult the official Hikvision security advisory (linked in References) for the specific patched firmware versions applicable to each model.
- Network mitigation: If immediate firmware patching is not possible, restrict internet-facing access to camera web interfaces by placing affected devices behind a firewall or VPN, preventing unauthenticated access from untrusted networks.
- Audit exposure: Identify all internet-exposed Hikvision DS-2CD, DS-2DE, DS-2DP, and DS-2TD Series cameras in your environment and prioritize remediation for any devices directly reachable from the public internet.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

