80+ OEMs Verified Vulnerable To Hikvision Backdoor

Author: Brian Karas, Published on Sep 22, 2017

Over 80 Hikvision OEM partners, including ADI, Interlogix, LTS, and Northern Video, have been verified as having products vulnerable to the Hikvision backdoor, deployed and exploitable over the public Internet.

IPVM ran tests to verify this using public data and the signature of the backdoor. Our test results found ~40% of all vulnerable devices were from OEMs, with the balance 60% being Hikvision own's branded products. In total, we estimate at least 250,000 devices vulnerable on the public Internet.

This vulnerability is particularly severe because it is simple to exploit and allows attackers to take over the camera by changing the admin password, view images, default the device, brick it, etc.

Demo

Our video below shows how even non-technical users can literally just copy/paste the backdoor string on to the end of a URL to vulnerable Hikvision and OEM partner cameras:

Top Brands Impacted

The following brands, ranked from highest to lowest, were the Top 10 most seen, making up ~30% of the total OEM units responding:

All 85 Brands Impacted

The following OEM brands, determined by associating model numbers returned in the query to specific companies, were identified in a global scan of online devices from a Shodan query:

**** ** ********* *** ********, ********* ***, **********, ***, *** Northern *****, **** **** ******** ** ****** ****************** ** *** ********* ********, ******** *** *********** **** *** ****** ********.

**** *** ***** ** ****** **** ***** ****** **** *** the ********* ** *** ********. *** **** ******* ***** ~**% of *** ********** ******* **** **** ****, **** *** ******* 60% ***** ********* ***'* ******* ********. ** *****, ** ******** at ***** ***,*** ******* ********** ** *** ****** ********.

**** ************* ** ************ ****** ******* ** ** ****** ** exploit *** ****** ********* ** **** **** *** ****** ** changing *** ***** ********, **** ******, ******* *** ******, ***** it, ***.

****

*** ***** ***** ***** *** **** ***-********* ***** *** ********* just ****/***** *** ******** ****** ** ** *** *** ** a *** ** ********** ********* *** *** ******* *******:

Top ****** ********

*** ********* ******, ****** **** ******* ** ******, **** *** Top ** **** ****, ****** ** ~**% ** *** ***** OEM ***** **********:

All ** ****** ********

*** ********* *** ******, ********** ** *********** ***** ******* ******** in *** ***** ** ******** *********, **** ********** ** * global **** ** ****** ******* **** ******* *****:

[***************]

  • *******
  • ****
  • *******
  • *********
  • *******
  • *****
  • *****
  • ******
  • ******** ***** *********
  • *****
  • *********
  • *****
  • **** **********
  • ****
  • ****** ********
  • ** ********
  • ***** ********
  • ***
  • ********
  • *******
  • *********
  • ******* ********
  • **********
  • *****
  • ***
  • ******
  • ***********
  • **** *****
  • ***** ****
  • *****
  • *******
  • *****
  • *******
  • *********
  • ** ******
  • **** ****
  • *******
  • *****
  • **********
  • *****
  • ******
  • ******
  • **&*
  • ******
  • ***** (***** ******** **** ******* *********)
  • ***
  • ***
  • *****
  • ******
  • ****
  • *****’* ********
  • *********
  • *******
  • ***** **********
  • *******
  • ***
  • ******
  • **** *******
  • ****** **
  • *******
  • ********* ***
  • *** ******
  • **********
  • ***
  • ******
  • *********
  • ********
  • ****** *********
  • ********
  • ***** **********
  • *****
  • ******
  • ********
  • ****
  • *******
  • *******
  • ******
  • ***** *******
  • ************
  • *-***
  • ******* ***** **********
  • *****
  • *******
  • ***

OEMs ***** ********* ******** *****

******* ** *** ***** **** **** **** ******** ******** ********* of ******** *********** ** ********** ** ******* ************** *******, *** the **** ********, *** ********** ****** **, *** ****** ****** all ******.

**** ****, **** ** **********, **** ******* **** **** *** additional ***** ******** ******** ** *****, *** ***** **** *** be **** ** **** *****, ** **** *** **** **** they **** ********** *** *************** ******** ** *********'* ******** ********.

OEM ********* ********* ****

**********, ********* ***** ********* *** ****** **** * ******* **** than ********* ***** *********-******* *********. **** ** ********* *** ** the ********* *******:

  • *********'* **** ************** ****** ***************, ********* "******* *********" **** ***** incidents *** **** ****** ** **** ** ********* (********* ***** **** *** ******** ****** *** **** *** *****)
  • **** *** ********* ****** ** **** ******** *******/******* ** ***** own, *** **** **** *** ********* ** ******* ******* ******** to ****.
  • *** ***-***** **** ****** *** ***** ***** ******** *** ******** made ** *********, **** **** ** *** **** ** *************** for "***-***", **** ****** "***-***" ** ****** **** * ********* unit **** * ****** ***** ******.

Updated ******** ***** *** *********

**** ** *** ******** **** **** ***** *** ******** ******* firmware. *** *******, *********** **-************* ******** ** ~**% ** *** ******* *** ********, **** several ****** ********* *** **.*.* ***** **** ***** ** *** latest ********* ******** ** ********'* *******, ******** ** ****** ****, months ***** ********* ******** ***** *** ***** ********. **** ********* that *** ****** ******** **** **** *** *** *********'* *** software *************, ******* **** *** ***** ********* ********** *** * longer ****** ** ****.

Firmware ******** ********

** ********* ***** ***** *** *** ******** *****, *** ******** showed ******** ******** **** * **** ***. ***** **** ** these ***** *** ************, *** *** *** **** ******* *********, many **** ********* ******* ****** *** *** ********.

Methodology ****

****'* ******* *********** ********* **:

  • ****** ** **,*** ******* **** ******* ***** *** ********* *******
  • ***** **** ****** *** ****** **** ***** ******** ******* (*.*.:****** **** **** *** ********* **** **** ******) ** ****** *************
  • *** ***** ******* ******** ** ******** ********* ****** (*.*.: **-* = *********, **-*** = ********, **-* = *-***, ***.)
  • ******* **** ** ****** ******
  • ******* ****** ** *********** ** **** ***** ** ***** ******* to ********* **** ******

What ** ** ** **** ***** ** ** *** ****

[******] - **** ******* *** ****** ***** ******* ***********, ***** on * ******* **** "*********** **********#*" ** ******* **** *** impacted ********* ******* ****** ** **** ***********, *** ********** **** to ** ******* ***** ******** ** * *******.

** ********* *** ******* **** ******** ** ********* ** **** unit ** ** **** * ********* *** (** **** ** these ****** ****** ******* **** ****, ** ****** **** ******** OEMs). ** *** ** **** * ********* *******, *** **** reliable ******** ***** ** ** ******* ** **** * **** secure *******. ******* ****, *********** ******* ****** ** *** ******, and ******* ****** ** ** * ********* **** **** ** other *****, ***-******** ****, *** ****** **** ****** *** ******* of **********.

**** *** ** ******** ** ******** ****** *************, ** **** often *** ** ******* ** **** **** *********** **** **** their *** *********. *** *** **** **** **** ****** ** see ** ** ** ********** ** ******* *** ****** "****://*************:****/*****-****/********?****=************" into * *******, ********* "*************" **** *** ******'* *** ** if *** *** ******* **********, ** **** *** *** ** or ******** ** ******* **********.

Comments (30)

***** ****, ****** ***** *** **** ********!

**** ** *****. *'* **** ** *** **** **** *** Dahua ** ****.

*** ****** ** ** **** ******** ** *** **** ****** vulnerable ********* *** ** **** *****?

****** -*** ******** ***** ***** ******** ******* ******* ********, ***., ***** quote:

** ****, *** ******* *** ****** ******** **** **** **** open ** ****** *******, *** ** **** ********* *********, ** anyone **** *** *******’ ******** *******.

*** ******* **** ***, *** *** ** ** **** *** unit ** ****** * ***? ;)

** **** **** *** **** ** **** *** *** **** exploit ** ** ********* ** ** ***% **** :-)

****** ****!

**** ** *** ***** *** ***** *** *** ***** ***** octets ** *** *** ******* ** ********* *** ******, **** OEM's ***'* ****** ****, ** **'* ***** **********.

*** *** **** ****** ** *** / *** ***** ** you ****** **. ****** ******.

*** ******** ******** ****: *****://********.***/***.**

[****]

*****://********.***/***/******/*********

*** ******* **** *** ***** ***** ****** ** **** ****** MAC *******.

** *** ***********, *** *** *** *** **** ****, *** should *** * ***** ***** ******* ** *** ****** **** giving ** *** ******* *** ****. ** *** *** *** URL *** *** * ***, ** ** **** ****** *** a ********* ******.

************, *** ********** ** *** ****** *** * ********** ******** from **** ********, ** ********* ******** **** **** ** ***** IP ******* *** ******** ********** *** **** ***** ** ******* are ** ***** *** ********* **** **** ** ***** *****, non-security ****, *** ******.

****** ** *** * ****** **** ******** *** ****** '**-******' in *********'* ***** **** *** ****** **** ** ****, ********* the *** ** ******* *** *** ******** ********. **** **** agree **** **** *** ********* ********* ** *****? * ******** this * '******', ***** * ****** ******, **** **** ***** line ** ******** **** *** **** **** **** ********* *** be ******** **** * ********. *** *** ****** **** **** 'hikvision **** ** ****' ** **** ** ** *** ***** 50% ** **** ********? *** ***** *** **** *********** ** hikvision ** ***** ** ** **** **** ******* **** ***-*****.

**** ******** ********* **** **** ********* ***** *** ******* *** 100+ **** *** ** **** *** **** * ****** ********* to ****** ** *** ******** *** ** ***** ****** ***** quite ******** ****** ***** **** *** ************ ** *** **** company, **** ** ****** ** *** '****'.

*** **** ************** ** *** **** *** ******** *** ******* security ***** ** ** ****** ****** ***** ********/*** *******, ******* them, *** ******** ********* **** ******. **** ** *** **** way *** *** ** **** *** *** *** ******* ** Hikvision's ******** *****, ** ******** **** **** **** ******* ********.

****** ** *** * ****** **** ******** *** ****** '**-******' in *********'* ***** ****

* ***** *** **** ** **-**** **** **** *** **** a ****** ** ***** ** ******* **** **********. ****, *** 'opinions' ** *******'* *** ** ******* ** ******* ****** **** are ****** **** ** **** *********** ******** *************.

***** *** **** ****** ******* ***** ** ******* ************* *******, like ********* *******, ** * *******, *** **** ** *** eliminate **, *** ****** *** ** ********** ********** **********, *** should *********.

***** *** *** ****** *** **** *************, * **** ******* the ********** ** ******** ******* *** **** **** ***** ***** should ****** ** ******* **** ******* ******** *** **** ********.

** *** ** ******* *** **** ** ** **** *** exception ** ******** *** **** **************? * **** ***, **** you ****** ** ****** **** **** ******?

*** *** ******* ****** ****** ******* ********* *** ****** ** evaluate *********'* ******** ******* ******** *************** **********. * *** *** say "*** ** ******* *** **** ** **", ******* ***** are * ****** ** ******* **** ***** ************* ****** ***** records **** *********, *** ** *** *** ********* ***** ******* security **** *** ***** *** ***** ************.

** *** **** ** **** * *****, ******** ********, ** put ** **** ********** (******* ** *** * *** ****) regarding ********* **. ***** *************, *** *** ******* ** ** so. *** ** *** *** ***** ** ******** **** *** point ** ***** ******* ***** ** ****** ****** ** ******* to **** **** ******** ** **** **** ** ******* **** out ****.

** *** ******* **** ******* ** * ********* ******* *** simply ****** *** "**** ** **** *** ****** ** ******" effect. *** ** *** ****** *** *************. ******** **** ** that ******* *** ***** ****** *** ******. (*** **'* **** SECURITY ******* - "*** ***** ***** ** **** *****?")

********* **** ******* **** ******** **** *** ***'** ***** ******** around *** ****. ** *** ****** **** ** ******* ** your *** **** ***'** *** ** *** "**** ********" **** have ** ***** ***** ********* *** **** ***?

*’* **** **** ** *** **** ***** ****** ***** *** this.

*’* **** **** ** *** **** ***** ****** ***** *** this.

* ****** ********** ** ***** **** ** ***** ***********.

**** *** *** *** ********.

***** ****** ** **** ** ********* ** *** ******** ***** blog *** ************* ** * ** ******** ** ***.

****, **** ***** *** *** *** ***********. **** ** * think? * ***** ** ** ****** ** *** **** *** IP ****** ***-*****-*******-****** ** ****** **** **** ** **** ** any **** ********** **** *** *****. *** ****** *** *** could ** *********** ** * ***** **** *** ****** *** be ** ***** ** ******* *** ********* ***** **** ** Hikvision ** **** ** **, * *** ******* ******** ** desperation. ** *** ********** ***** **** ******** ******** *** ******** as **** *** ** ******* ***** *****. *** **** *** concede **** ** ***** * ***** (* ******) **** ********* intent ** **** **** ********* ******* ** ******** ******* ** won't ****** ******* ******* ** ******* *** **** ******* ** not *** ********* ******.**** ** *** **** ******** **** *** folks **** **** ****, (***** * ****** ** **** **). If *** **** ********** ***** *** ****** ** ** *** the ***** ** *******, *****? ** ***** ** ** **** to **** *** *** ** **** "*" *******? **** ***** this ** * ******** ******* *****, ******* ** ** ** fodder.

***** *** * **** ** *** ***** **** ** **** ask.

******* ** *******, *** ** *** *** ** **** ********?

********* ***'* **** *****, ***** ***** *****.

*** *** **** **** ***** *** **** ****** ****** ** 5? ***'* **** *** ****? ****** ******* **** **** *** your **** ******? **** *** *** ****** **? **** *********, unprofessional, ******** ******** **** *** **** ***** ***** ****** ****** UM. ** ***** * *** **** ** **********, **** ** open ************ *** ***** ** ******** **** ****** ******* **********, what ***** ***?

*** ** *** *** ** **** ********?

** #***, * ********. * ***** ********* ***** ** ********. Marty ****** ********* **** ** ****** ** **** ********** **** others ***** ***** *** ******* ** *********'* ******** ********* ** a ******* *** ****** ** ****. ***? ******* ** ***** how ********** ****** ** ********** ***** ************* ** ** ** say ********* **** **** ** ***** ** *** ****** *** dangerous *** ********* ******** **.

** ***** * *** **** ** **********, **** ** **** conversation

** ****, *****, *** *** *********** **** ***** ** ****.

*****, **, ** *** **.

** ****** *******, ****** **** **** **** ** ******* ***** security ************** ** *** **** **** ***** **** ***** ****** makes. **** ***'* **** ****.

*** *** ****** ***** ****?

** *** *** ****** *********** ******* **** ****** *** *** VMS ***** ***'* ** ********* "*** ** *** ******" ******. That's *** ** **** ******* ****** ** *** ******** ******** TLS. *** *** **** ******* ** ********** *** **** **** week's ****-***** ****** *******.

* ***'* ********** *** *** ********* **** ****** ** ****** an ******* **** ** ** ********** **** **********. ***** ******** that *** ***** ** ***** *******, **** ** **** *** bad, *** ***** **** ********* ** ********* ** ****** **** a ******** *** ****** ********* ** *** ** *** ***. I ***** *** **** **** ** *** **** ****** *** I ****** ****** ********* ** ******* ** ******* ***. *** delay ** ********* ***-********* ** * ******** ***** ** ****** troubling.

**** ** **** *** **** ****** * **** ***** ***** Digital ******** ***** **** ** ********** ******* ***** ********. **** there *** *** ***** ** *** **** ****** ** ******** be ******** ** **. ** ***** ***** **** ******** *******, it ******* * *** ****. **********, ** * **** ********* in *** ****, * **** *** **** **** ******* ***** has **** **** ** ******* ** **** ** **** *** serious ******.

* ***** ******** ** *** *** ******* ********* *******, *** they ***** ******** **** *** ******** *** **** *** ********* on * ****** ****. *** ***** ******** *** ****** ********.

* **** *** **** * ***'* ***** *** ************ ******** cloud ******** ** *******. * **** ******* *** ** ** personal ********* ******* **** *** ****** ******. * ******* *** firmware *** *** ******** ****** **** *** ******** *** ***** enabled *****.

** ** ******* ** *** *** ***** **** ** **** Hikvision ***** ******** *** *** ***** **** *********'* **** ** security ***** *********** ********* *** **** **** **** ** **** a *** ** **** **** ***'* **** ******* ******** ********* and **** ***** ***'* ******** ***** ******** ** *** ********.

* ***** ******** **** *** *** ** ****** *********. ***** I ***** ********** ***** *** ********* ****** ** ******** * would ***** ** ** ****** ** ****** *** **** *** source ****** **** ******* *** ****** ***** ******* ** *** claims ** **** ********* *** *******. *** *** **** ****** have ***** *********** *** *** ****** ** ********, ******** **** company ***** ** ******** ** **** ***** ******* **** *** road. * ***** ***** **** ** ***** **** ***'* **** the ********* ** **** **** *** **** ** *********** ******* in ***** ** ******* *********. ***** ***** *** ********* **** who ***** ******* * ***** ** *** $**/****** ******* ***** the ****** ** ******* **** ***?

********** *******: ****** ***** ***** ***** ****** ** *** **** to ** *** **** - *** ******* *** ****** ***** have ** *** *** ****** *******. *** *** ***** ********** (almost *****) **** ** ** ** *** *** ***** **** would ************ ** ****** ************ **** *** ************ ** * result. **** ****** ***** ******** ****** *************** ** ***** ** remedied. **** ****'* ****** ***** ****** ******* ******* ***** *** drivers **** *** ******* ********, ******* *** **************.***, *** ******* became **********.

**** **** ****** ***** *******. ******* **** ** ***** **** their ******* ******* ** ********* *** *** **** ****** **** will **** ** **** *** **** ********** ********* ** ******* to *** ******* ***** ***** *****. ***'* ****** **** ***** defenders ** *** ***** ******** **** ** **** **** * seemingly ***** ****** **** ** ****. * ****** **** **** bought *** ***** ******** ** **** *****, ** ** **** cases * *** ******* **** ******* ** ** ****** ** by **** ************ ********** ***** *** **** ******* ****** *** their ********* ********. ******* *** ** **** **** *** **** they **** * ******* ***** *** * **** **** ******* when ** ***** ** ***** ******** ** *********. ******** **** some *********, ** ******** *** ** **********, ****** **** ** quotes *** *** ********* **** ***** *** *********** **** **** expensive ******** ** ******** *** ****** *** *******?

** ****** *** *** ********* **** ***** *** *********** **** more ********* ******** ** ******** *** ****** *** *******

**********:****** ****** *********.

** ********, ******, #**, *** *** **** *** ********* ********** that ******* ********** ** **** **** **** **** *********.

** *** ***** ****, * ** ***** **** *** ******* that **** ****-**** ********* *********** *** *** **. ** **** go **** *** *** "*** ** ********, * **** *** these ***** *** **** ******* **** *** **** *** ** have * ******** ** ** *** *** ************ ** * subsidiary ** *** ******* **********", **** **** * ******* ** scary ********.

**** ** *** **** '** ********' ****? *** ** **** relevant '** ********'? ** ****** ** **** **** ** ***** scenario ** ***** ****** ** ****** **** *** ***** ************ is **** ***** ****. ** ******* ***** ***'* ****** ***** on **** *** **** ******* ** **** ********** ****,**** ***** be * ****** ***** ** *** '****** ******' *****'** **?

*'* *** ** ********** ** *********, *** **** ****** **** friends *** * ****** ** *** ** ****** *** **** in ***** ****. ******* ***** *** ******* *** *******...

*'* **** ** ** * ******* **** *** **** ******* these ** ***-**** *** *-* *****.

*** *** **** ** **** ***** ********* **** **** **** selling **** ********* *** *-* ***** **** ****** *** ** around ** *-* **** ***** ** **** **** *** **** boxes ** **** *********. ** ************* ** ****** ***** **** to *** ******** **** ***** **** ** **** **** ***** cables *** **** * ****** *** ** *** *******

**** *** **** **** **** ******* **** **** ****** ********* those *** ****** **** ***** ***** ****** *** ****** * one **** **** *** ****** ** * ****.

Login to read this IPVM report.
Why do I need to log in?
IPVM conducts unique testing and research funded by member's payments enabling us to offer the most independent, accurate and in-depth information.

Most Recent Industry Reports

IP Camera Installation Tool Shootout - Avigilon, Axis, Ideal, Hanwha, Triplett, Veracity on Oct 23, 2018
Setting up IP cameras has historically been challenging, with techs often precariously using a laptop on a ladder or lift. Some options for install...
ADT and Brinks Home Security Struggles Impact On Industry Examined on Oct 23, 2018
ADT and Brinks Home Security have both been struggling over the last year. ADT valuation is 50%+ less than their IPO target. Brinks Home Security,...
Hikvision Growth Declines Q3 2018 on Oct 22, 2018
Hikvision's growth continues to decline in 2018 going from: Q1 - 33% Q2 - 22% Q3 - 14.6% In this note, we examine Hikvision's newest Q3...
Geutebruck Company Profile on Oct 22, 2018
Geutebrück has been in business for nearly 50 years, but they are not well known within the US surveillance market. In this report, we profile...
Chinese Government Blocks IPVM on Oct 22, 2018
IPVM has been blocked by the Chinese government without any notice or explanation. This means IPVM.com is no longer officially accessible anywhere...
Startup SafePass Profile on Oct 19, 2018
A major problem with visitor management is that the systems mostly require adhesive printed paper labels and paper logs, creating waste and an...
China Is Not A Security Megatrend, Says SIA on Oct 19, 2018
The US Security Industry Association has released its 10 "Security Megatrends" for 2019. SIA declares that these megatrends, such as "Advanced...
Hanwha Dual Imager Dome Camera Tested (PNM-7000VD) on Oct 18, 2018
Hanwha has introduced their first dual-imager model, the PNM-7000VD, a twin 1080p model featuring independently positionable sensors and a snap-in...
Camera Height / Blind Spot Added to IPVM Camera Calculator on Oct 18, 2018
IPVM has added camera height and blind spot estimation to the Camera Calculator. This is especially helpful for those who need to mount cameras up...

The world's leading video surveillance information source, IPVM provides the best reporting, testing and training for 10,000+ members globally. Dedicated to independent and objective information, we uniquely refuse any and all advertisements, sponsorship and consulting from manufacturers.

About | FAQ | Contact