🔴 CVE-2017-7921

Authentication bypass vulnerability in Hikvision IP cameras allows attackers to escalate privileges and gain unauthorized access. The vulnerability is classified as CWE-287 (Improper Authentication) and is actively exploited in the wild according to CISA KEV.

← Back to Overview
HIGH_RISK
Risk Level
9.8
CVSS Score
NETWORK
Attack Vector
Initial Access
ATT&CK Tactic
T1190 — Exploit Public-Facing Application
ATT&CK Technique
VERY_HIGH
Deployment Risk
No
Ransomware

📋 Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: DIRECT_NETWORK

CVE Published: 2017-05-06

Added to CISA KEV: 2026-03-05 3225 DAYS BETWEEN CVE AND KEV

🎯 Recommendations:

🔍 Web Intelligence (Kagi · 2026-06-04)

CVE-2017-7921 is a critical vulnerability involving improper authentication in various Hikvision IP camera models [1] [3]. Because of its severity and ease of exploitation, it is included in the Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) Catalog [1].

Exploitation and Impact
  • Active Exploitation: The vulnerability is actively exploited in the wild, which is why it is listed in the CISA KEV catalog [1].
  • Attack Method: The flaw is an "Improper Authentication" issue, meaning the device fails to correctly verify user credentials during the login process [2] [3].
  • Requirements: It is a remote, network-based attack that does not require physical access to the device [3]. It typically does not require complex user interaction to execute.
  • Impact: Successful exploitation allows an attacker to bypass authentication, potentially gaining unauthorized access to the device, escalating privileges, and accessing sensitive information (such as video feeds or system configurations) [2] [4].
  • PoC Availability: Proof-of-concept (PoC) exploit code is publicly available on platforms like GitHub, often shared for educational or security research purposes [5].
Affected Products and Mitigation
  • Affected Versions: The vulnerability primarily affects Hikvision DS-2CD2xx2F-I Series cameras running firmware versions from V5.2.0 (build 140721) up to V5.4.0 (build 160530) [1]?id=CVE-2017-7921.
  • Status: This is a legacy vulnerability. The primary mitigation is to update the affected devices to the latest firmware versions provided by Hikvision for the specific model and region [4] [3]. Users are advised to consult Hikvision’s official security notifications to identify the specific "resolved" (patched) build for their hardware [3].
While information regarding specific, named ransomware campaigns targeting this exact CVE is less centralized than for more modern vulnerabilities, its inclusion in the CISA KEV catalog indicates that it is a high-priority target for threat actors and should be patched immediately to prevent unauthorized access and potential follow-on attacks [1].

Sources

  1. NVD - CVE-2017-7921

    This CVE is in CISA's Known Exploited Vulnerabilities Catalog Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements. ... Description. An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0…

  2. CVE-2017-7921-EXPLOIT/README.md at main...

    A PoC exploit for CVE-2017-7921 - Hikvision Camera Series Improper Authentication Vulnerability. - CVE-2017-7921-EXPLOIT/README.md at main · K3ysTr0K3R/CVE-2017-7921-EXPLOIT.The flaw identified in the affected Hikvision camera series is an "Improper Authentication" issue. This vulnerability arises w…

  3. CVE-2017-7921: Hikvision Improper Authentication Vulnerability

    CVE-2017-7921 is an improper authentication flaw in certain Hikvision IP camera firmware that can enable privilege escalation. See affected versions, patches, and mitigations. ... CVE-2017-7921 affects specific Hikvision IP camera series running vulnerable firmware build ranges identified by Hikvisi…

  4. CVE-2017-7921: Hikvision Cameras Improper Authentication...

    Learn about CVE-2017-7921 affecting Hikvision Cameras, allowing improper authentication and unauthorized access. Find mitigation steps and long-term security practices. A vulnerability in Hikvision Cameras has been identified, allowing for improper authentication and potential elevation of privilege…

  5. CVE-2017-7921 - Hikvision Camera Series Improper Authentication ...

    A security flaw identified as CVE-2017-7921, which affects various models of Hikvision cameras. The vulnerability was discovered in the DS-2CD2xx2F-I Series ... CVE-2017-7921 - Hikvision Camera Series Improper Authentication Vulnerability.Exploitation. It's crucial to emphasize that exploiting this…