MBSD-SOC reported a sharp rise in exploitation attempts against Hikvision network cameras using CVE-2021-36260, an unauthenticated OS command injection flaw in the products’ web server component. The vulnerability stems from improper input validation and can allow remote code execution as the root user by sending crafted requests to the device.
The observed attacks used a PUT request to /SDK/webLanguage and injected commands through XML content, with MBSD-SOC noting detections increased significantly after May 26, 2023. Telemetry showed most attack traffic originated from the United States, followed by Germany, Japan, France, and Romania, underscoring continued broad internet scanning and exploitation of exposed Hikvision devices.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
MBSD-SOC published its May 2023 detection trends and highlighted increased attacks targeting CVE-2021-36260 in Hikvision network cameras. Its telemetry showed most apparent attack sources in May were from the United States, followed by Germany, Japan, France, and Romania.
MBSD-SOC reported that detections of attacks targeting CVE-2021-36260 increased after Friday, May 26, 2023, following intermittent observations earlier in the year. The observed exploit traffic used HTTP PUT requests to /SDK/webLanguage with command injection embedded in XML.
The CVE record for CVE-2021-36260 was later updated. The source notes this update occurred after the original publication of the Hikvision vulnerability entry.
The CVE record for CVE-2021-36260 was published, documenting a command injection vulnerability in the web server of some Hikvision products caused by insufficient input validation. The flaw could allow attackers to send malicious commands and achieve command injection.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.