Tens of thousands of cameras have failed to patch a critical, 11-month-old CVE, leaving thousands of organizations exposed.

The global landscape of network-connected surveillance hardware is currently facing a significant security reckoning. New research from threat intelligence firm Cyfirma has identified that more than 80,000 Hikvision surveillance cameras remain vulnerable to a severe command injection flaw that was first disclosed nearly a year ago. Despite the critical nature of the vulnerability, classified as CVE-2021-36260, the continued existence of these unpatched devices across global networks represents a persistent risk to corporate, governmental, and private infrastructure.
Hikvision, a state-owned manufacturer based in Hangzhou, China, dominates a substantial portion of the global video surveillance market. Its reach extends across more than 100 countries, embedding its hardware into the critical infrastructure of transport hubs, retail chains, and government facilities. The persistence of this security gap is particularly concerning given the geopolitical scrutiny already surrounding the company; in 2019, the U.S. Federal Communications Commission (FCC) officially designated Hikvision as an "unacceptable risk to U.S. national security," citing concerns over data integrity and potential state-sponsored espionage.
Chronology of a Critical Vulnerability
The vulnerability in question, CVE-2021-36260, was formally disclosed in the autumn of 2021. It was assigned a CVSS (Common Vulnerability Scoring System) score of 9.8, the maximum possible rating for a vulnerability that can be exploited remotely without authentication. The flaw resides in the web server component of Hikvision cameras, allowing an unauthenticated attacker to inject malicious commands into the system via a crafted request.
Following the initial disclosure, Hikvision issued firmware updates intended to mitigate the risk. However, the disconnect between the release of a patch and its actual implementation on tens of thousands of individual devices highlights a widening gap in the cybersecurity posture of Internet of Things (IoT) hardware. Nearly 12 months after the initial notification, the fact that over 80,000 devices remain exposed suggests that either administrators are unaware of the risk, or the logistical challenge of updating distributed firmware remains insurmountable for many organizations.
The Rise of Opportunistic Exploitation
The danger is no longer theoretical. Cyfirma’s researchers have documented a marked increase in activity across various dark web forums—particularly those operating in Russian-language spaces—where threat actors are actively discussing methods to exploit this specific Hikvision vulnerability. These discussions frequently involve the trade of leaked credentials and the sharing of automated scripts designed to scan for vulnerable IP addresses.
The motive for such exploitation is multifaceted. While some actors may simply be looking to build botnets for distributed denial-of-service (DDoS) attacks or to participate in ransomware operations, the risk profile for Hikvision hardware is skewed toward state-level espionage. Analysts point to the potential involvement of advanced persistent threat (APT) groups, such as MISSION2025/APT41 or APT10, which have historically shown interest in gaining persistent access to surveillance networks to facilitate reconnaissance or to monitor sensitive geopolitical targets. The ability to intercept video feeds or pivot from a camera into a secure corporate network makes these devices high-value targets for intelligence agencies.
The Structural Vulnerability of IoT
The widespread failure to patch these devices is not merely a failure of individual users; it is a systemic issue inherent to the IoT industry. Unlike modern computing environments where operating systems like Windows, macOS, or Android utilize automated update mechanisms, IoT hardware often relies on manual intervention.
David Maynor, senior director of threat intelligence at Cybrary, suggests that the problem is rooted in the fundamental design philosophy of surveillance hardware. According to Maynor, Hikvision’s products frequently contain systemic vulnerabilities that go beyond a single CVE. Many units are shipped with default credentials, and even when a patch is applied, the lack of robust forensic capabilities makes it nearly impossible for a network administrator to verify whether a system was already compromised prior to the update. "We have not observed any change in Hikvision’s posture to signal an increase in security within their development cycle," Maynor noted, suggesting that the company’s current approach to security may not be keeping pace with the evolving threat landscape.
Barriers to Effective Remediation
The challenge of securing these devices is compounded by the "invisible" nature of IoT management. Paul Bischoff, a privacy advocate with Comparitech, emphasizes that the average user—often a small business owner or a residential consumer—is rarely equipped to manage the lifecycle of an IoT device.
"IoT devices like cameras aren’t always as easy or straightforward to secure as an app on your phone," Bischoff explained. "Updates are not automatic; users need to manually download and install them, and many users might never get the message. Furthermore, IoT devices might not give users any indication that they’re unsecured or out of date. Whereas your phone will alert you when an update is available and likely install it automatically the next time you reboot, IoT devices do not offer such conveniences."
This lack of transparency allows cybercriminals to thrive. Tools like Shodan and Censys, which index internet-connected devices, provide attackers with a searchable map of vulnerable hardware. If a camera is connected to the public internet with its default password and an unpatched firmware version, it can be identified and compromised in a matter of seconds. For many organizations, the realization that they are exposed only occurs after a breach has already taken place, at which point the attacker may have already established a permanent foothold in the internal network.
Broader Implications and National Security
The Hikvision situation underscores a broader, more alarming trend regarding the supply chain of critical security infrastructure. When millions of devices are deployed globally, the security of those devices effectively becomes a public safety issue. If these cameras are used in police departments, government offices, or critical utility providers, a single unpatched CVE can serve as a backdoor for hostile intelligence services.
The geopolitical tension between China and Western nations has further complicated the remediation of these vulnerabilities. With Hikvision facing ongoing sanctions and restrictions, the trust required to facilitate secure updates and transparent communication is effectively eroded. In the United States, the FCC’s 2019 ruling to label the company as a national security risk has led to a push for "rip and replace" programs, where local governments are encouraged to phase out Chinese-made surveillance equipment entirely. However, the cost and logistical burden of such programs mean that legacy devices will likely remain in operation for years to come.
The Future of IoT Security
To address this ongoing crisis, security experts suggest that a paradigm shift is required in how IoT manufacturers and regulators approach device security. This includes:
- Mandatory Security Standards: Regulators may need to enforce stricter baseline security requirements, such as requiring unique, non-default passwords for every individual unit and mandating secure-by-design principles.
- Automated Lifecycle Management: Future iterations of IoT hardware must prioritize automatic over-the-air (OTA) updates that do not require user intervention, ensuring that critical patches are pushed to all devices as soon as they are available.
- Improved Visibility and Reporting: Manufacturers should implement diagnostic tools that allow administrators to easily verify the security status of their entire fleet, making it clear when a device is out-of-date or exhibiting anomalous behavior.
- End-of-Life Policies: There must be a clear industry standard for when devices are no longer supported, with automated prompts to decommission equipment that can no longer be safely patched.
Until such changes are standardized across the manufacturing sector, the thousands of vulnerable Hikvision cameras—and countless other IoT devices—will remain open doors for cybercriminals and state-sponsored actors alike. The incident serves as a stark reminder that in an increasingly connected world, the security of the whole is only as strong as the security of the individual, often forgotten, hardware component on the edge of the network. As organizations continue to digitize their physical security, the gap between device convenience and robust cybersecurity remains the most significant threat to operational integrity.






