Summary
CVE-2026-61390 is a heap buffer overflow vulnerability affecting Hikvision DS-2CD Series and DS-2DE Series IP cameras. Unauthenticated remote attackers can trigger device malfunction by sending specially crafted network packets, with no user interaction required. The vulnerability carries a CVSS v3.1 base score of 7.7 (HIGH), with High Integrity and High Availability impact.
Technical details
- Root cause: Heap buffer overflow in the camera’s network-facing processing logic
- Trigger conditions: Sending specially crafted packets to the device over the network; no authentication or user interaction required
- Attack vector: Network (AV:N) — exploitable remotely from the internet; Attack Complexity is High (AC:H), indicating exploitation may depend on specific device or network conditions
- Impact: Device malfunction with High Integrity (I:H) and High Availability (A:H) impact, and Low Confidentiality (C:L) impact; the CVSS scoring is consistent with outcomes such as device state corruption, disruption of video surveillance functions, or potential for further unauthorized control of the device
Affected software
- Hikvision DS-2CD Series IP cameras — specific affected firmware versions are listed on Hikvision’s Security Firmware Download page
- Hikvision DS-2DE Series IP cameras — specific affected firmware versions are listed on Hikvision’s Security Firmware Download page
Severity
CVSS v3.1 Base Score: 7.7 (HIGH)
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H
| Metric | Value |
|—|—|
| Attack Vector | Network |
| Attack Complexity | High |
| Privileges Required | None |
| User Interaction | None |
| Scope | Unchanged |
| Confidentiality | Low |
| Integrity | High |
| Availability | High |
Mitigation and recommended actions
- Immediate: Apply the patched firmware released by Hikvision for your specific device model. Consult the Hikvision Security Firmware Download page to identify and obtain the correct patched firmware version for your camera model.
- If immediate patching is not possible:
- Restrict network access to camera management interfaces (ports 80, 443, 8000) using firewall rules or network segmentation — do not expose camera web interfaces directly to the internet.
- Place cameras behind a network perimeter that limits inbound packet delivery from untrusted sources.
- Monitor camera management interfaces for unexpected traffic or device reboot events that may indicate exploitation attempts.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

