80+ OEMs Verified Vulnerable To Hikvision Backdoor

Author: Brian Karas, Published on Sep 22, 2017

Over 80 Hikvision OEM partners, including ADI, Interlogix, LTS, and Northern Video, have been verified as having products vulnerable to the Hikvision backdoor, deployed and exploitable over the public Internet.

IPVM ran tests to verify this using public data and the signature of the backdoor. Our test results found ~40% of all vulnerable devices were from OEMs, with the balance 60% being Hikvision own's branded products. In total, we estimate at least 250,000 devices vulnerable on the public Internet.

This vulnerability is particularly severe because it is simple to exploit and allows attackers to take over the camera by changing the admin password, view images, default the device, brick it, etc.

Demo

Our video below shows how even non-technical users can literally just copy/paste the backdoor string on to the end of a URL to vulnerable Hikvision and OEM partner cameras:

Top Brands Impacted

The following brands, ranked from highest to lowest, were the Top 10 most seen, making up ~30% of the total OEM units responding:

All 85 Brands Impacted

The following OEM brands, determined by associating model numbers returned in the query to specific companies, were identified in a global scan of online devices from a Shodan query:

**** ** ********* *** ********, ********* ***, **********, ***, *** Northern *****, **** **** ******** ** ****** ****************** ** *** ********* ********, ******** *** *********** **** *** ****** ********.

**** *** ***** ** ****** **** ***** ****** **** *** the ********* ** *** ********. *** **** ******* ***** ~**% of *** ********** ******* **** **** ****, **** *** ******* 60% ***** ********* ***'* ******* ********. ** *****, ** ******** at ***** ***,*** ******* ********** ** *** ****** ********.

**** ************* ** ************ ****** ******* ** ** ****** ** exploit *** ****** ********* ** **** **** *** ****** ** changing *** ***** ********, **** ******, ******* *** ******, ***** it, ***.

****

*** ***** ***** ***** *** **** ***-********* ***** *** ********* just ****/***** *** ******** ****** ** ** *** *** ** a *** ** ********** ********* *** *** ******* *******:

Top ****** ********

*** ********* ******, ****** **** ******* ** ******, **** *** Top ** **** ****, ****** ** ~**% ** *** ***** OEM ***** **********:

All ** ****** ********

*** ********* *** ******, ********** ** *********** ***** ******* ******** in *** ***** ** ******** *********, **** ********** ** * global **** ** ****** ******* **** ******* *****:

[***************]

  • *******
  • ****
  • *******
  • *********
  • *******
  • *****
  • *****
  • ******
  • ******** ***** *********
  • *****
  • *********
  • *****
  • **** **********
  • ****
  • ****** ********
  • ** ********
  • ***** ********
  • ***
  • ********
  • *******
  • *********
  • ******* ********
  • **********
  • *****
  • ***
  • ******
  • ***********
  • **** *****
  • ***** ****
  • *****
  • *******
  • *****
  • *******
  • *********
  • ** ******
  • **** ****
  • *******
  • *****
  • **********
  • *****
  • ******
  • ******
  • **&*
  • ******
  • ***** (***** ******** **** ******* *********)
  • ***
  • ***
  • *****
  • ******
  • ****
  • *****’* ********
  • *********
  • *******
  • ***** **********
  • *******
  • ***
  • ******
  • **** *******
  • ****** **
  • *******
  • ********* ***
  • *** ******
  • **********
  • ***
  • ******
  • *********
  • ********
  • ****** *********
  • ********
  • ***** **********
  • *****
  • ******
  • ********
  • ****
  • *******
  • *******
  • ******
  • ***** *******
  • ************
  • *-***
  • ******* ***** **********
  • *****
  • *******
  • ***

OEMs ***** ********* ******** *****

******* ** *** ***** **** **** **** ******** ******** ********* of ******** *********** ** ********** ** ******* ************** *******, *** the **** ********, *** ********** ****** **, *** ****** ****** all ******.

**** ****, **** ** **********, **** ******* **** **** *** additional ***** ******** ******** ** *****, *** ***** **** *** be **** ** **** *****, ** **** *** **** **** they **** ********** *** *************** ******** ** *********'* ******** ********.

OEM ********* ********* ****

**********, ********* ***** ********* *** ****** **** * ******* **** than ********* ***** *********-******* *********. **** ** ********* *** ** the ********* *******:

  • *********'* **** ************** ****** ***************, ********* "******* *********" **** ***** incidents *** **** ****** ** **** ** ********* (********* ***** **** *** ******** ****** *** **** *** *****)
  • **** *** ********* ****** ** **** ******** *******/******* ** ***** own, *** **** **** *** ********* ** ******* ******* ******** to ****.
  • *** ***-***** **** ****** *** ***** ***** ******** *** ******** made ** *********, **** **** ** *** **** ** *************** for "***-***", **** ****** "***-***" ** ****** **** * ********* unit **** * ****** ***** ******.

Updated ******** ***** *** *********

**** ** *** ******** **** **** ***** *** ******** ******* firmware. *** *******, *********** **-************* ******** ** ~**% ** *** ******* *** ********, **** several ****** ********* *** **.*.* ***** **** ***** ** *** latest ********* ******** ** ********'* *******, ******** ** ****** ****, months ***** ********* ******** ***** *** ***** ********. **** ********* that *** ****** ******** **** **** *** *** *********'* *** software *************, ******* **** *** ***** ********* ********** *** * longer ****** ** ****.

Firmware ******** ********

** ********* ***** ***** *** *** ******** *****, *** ******** showed ******** ******** **** * **** ***. ***** **** ** these ***** *** ************, *** *** *** **** ******* *********, many **** ********* ******* ****** *** *** ********.

Methodology ****

****'* ******* *********** ********* **:

  • ****** ** **,*** ******* **** ******* ***** *** ********* *******
  • ***** **** ****** *** ****** **** ***** ******** ******* (*.*.:****** **** **** *** ********* **** **** ******) ** ****** *************
  • *** ***** ******* ******** ** ******** ********* ****** (*.*.: **-* = *********, **-*** = ********, **-* = *-***, ***.)
  • ******* **** ** ****** ******
  • ******* ****** ** *********** ** **** ***** ** ***** ******* to ********* **** ******

What ** ** ** **** ***** ** ** *** ****

[******] - **** ******* *** ****** ***** ******* ***********, ***** on * ******* **** "*********** **********#*" ** ******* **** *** impacted ********* ******* ****** ** **** ***********, *** ********** **** to ** ******* ***** ******** ** * *******.

** ********* *** ******* **** ******** ** ********* ** **** unit ** ** **** * ********* *** (** **** ** these ****** ****** ******* **** ****, ** ****** **** ******** OEMs). ** *** ** **** * ********* *******, *** **** reliable ******** ***** ** ** ******* ** **** * **** secure *******. ******* ****, *********** ******* ****** ** *** ******, and ******* ****** ** ** * ********* **** **** ** other *****, ***-******** ****, *** ****** **** ****** *** ******* of **********.

**** *** ** ******** ** ******** ****** *************, ** **** often *** ** ******* ** **** **** *********** **** **** their *** *********. *** *** **** **** **** ****** ** see ** ** ** ********** ** ******* *** ****** "****://*************:****/*****-****/********?****=************" into * *******, ********* "*************" **** *** ******'* *** ** if *** *** ******* **********, ** **** *** *** ** or ******** ** ******* **********.

Comments (30)

***** ****, ****** ***** *** **** ********!

**** ** *****. *'* **** ** *** **** **** *** Dahua ** ****.

*** ****** ** ** **** ******** ** *** **** ****** vulnerable ********* *** ** **** *****?

****** -*** ******** ***** ***** ******** ******* ******* ********, ***., ***** quote:

** ****, *** ******* *** ****** ******** **** **** **** open ** ****** *******, *** ** **** ********* *********, ** anyone **** *** *******’ ******** *******.

*** ******* **** ***, *** *** ** ** **** *** unit ** ****** * ***? ;)

** **** **** *** **** ** **** *** *** **** exploit ** ** ********* ** ** ***% **** :-)

****** ****!

**** ** *** ***** *** ***** *** *** ***** ***** octets ** *** *** ******* ** ********* *** ******, **** OEM's ***'* ****** ****, ** **'* ***** **********.

*** *** **** ****** ** *** / *** ***** ** you ****** **. ****** ******.

*** ******** ******** ****: *****://********.***/***.**

[****]

*****://********.***/***/******/*********

*** ******* **** *** ***** ***** ****** ** **** ****** MAC *******.

** *** ***********, *** *** *** *** **** ****, *** should *** * ***** ***** ******* ** *** ****** **** giving ** *** ******* *** ****. ** *** *** *** URL *** *** * ***, ** ** **** ****** *** a ********* ******.

************, *** ********** ** *** ****** *** * ********** ******** from **** ********, ** ********* ******** **** **** ** ***** IP ******* *** ******** ********** *** **** ***** ** ******* are ** ***** *** ********* **** **** ** ***** *****, non-security ****, *** ******.

****** ** *** * ****** **** ******** *** ****** '**-******' in *********'* ***** **** *** ****** **** ** ****, ********* the *** ** ******* *** *** ******** ********. **** **** agree **** **** *** ********* ********* ** *****? * ******** this * '******', ***** * ****** ******, **** **** ***** line ** ******** **** *** **** **** **** ********* *** be ******** **** * ********. *** *** ****** **** **** 'hikvision **** ** ****' ** **** ** ** *** ***** 50% ** **** ********? *** ***** *** **** *********** ** hikvision ** ***** ** ** **** **** ******* **** ***-*****.

**** ******** ********* **** **** ********* ***** *** ******* *** 100+ **** *** ** **** *** **** * ****** ********* to ****** ** *** ******** *** ** ***** ****** ***** quite ******** ****** ***** **** *** ************ ** *** **** company, **** ** ****** ** *** '****'.

*** **** ************** ** *** **** *** ******** *** ******* security ***** ** ** ****** ****** ***** ********/*** *******, ******* them, *** ******** ********* **** ******. **** ** *** **** way *** *** ** **** *** *** *** ******* ** Hikvision's ******** *****, ** ******** **** **** **** ******* ********.

****** ** *** * ****** **** ******** *** ****** '**-******' in *********'* ***** ****

* ***** *** **** ** **-**** **** **** *** **** a ****** ** ***** ** ******* **** **********. ****, *** 'opinions' ** *******'* *** ** ******* ** ******* ****** **** are ****** **** ** **** *********** ******** *************.

***** *** **** ****** ******* ***** ** ******* ************* *******, like ********* *******, ** * *******, *** **** ** *** eliminate **, *** ****** *** ** ********** ********** **********, *** should *********.

***** *** *** ****** *** **** *************, * **** ******* the ********** ** ******** ******* *** **** **** ***** ***** should ****** ** ******* **** ******* ******** *** **** ********.

** *** ** ******* *** **** ** ** **** *** exception ** ******** *** **** **************? * **** ***, **** you ****** ** ****** **** **** ******?

*** *** ******* ****** ****** ******* ********* *** ****** ** evaluate *********'* ******** ******* ******** *************** **********. * *** *** say "*** ** ******* *** **** ** **", ******* ***** are * ****** ** ******* **** ***** ************* ****** ***** records **** *********, *** ** *** *** ********* ***** ******* security **** *** ***** *** ***** ************.

** *** **** ** **** * *****, ******** ********, ** put ** **** ********** (******* ** *** * *** ****) regarding ********* **. ***** *************, *** *** ******* ** ** so. *** ** *** *** ***** ** ******** **** *** point ** ***** ******* ***** ** ****** ****** ** ******* to **** **** ******** ** **** **** ** ******* **** out ****.

** *** ******* **** ******* ** * ********* ******* *** simply ****** *** "**** ** **** *** ****** ** ******" effect. *** ** *** ****** *** *************. ******** **** ** that ******* *** ***** ****** *** ******. (*** **'* **** SECURITY ******* - "*** ***** ***** ** **** *****?")

********* **** ******* **** ******** **** *** ***'** ***** ******** around *** ****. ** *** ****** **** ** ******* ** your *** **** ***'** *** ** *** "**** ********" **** have ** ***** ***** ********* *** **** ***?

*’* **** **** ** *** **** ***** ****** ***** *** this.

*’* **** **** ** *** **** ***** ****** ***** *** this.

* ****** ********** ** ***** **** ** ***** ***********.

**** *** *** *** ********.

***** ****** ** **** ** ********* ** *** ******** ***** blog *** ************* ** * ** ******** ** ***.

****, **** ***** *** *** *** ***********. **** ** * think? * ***** ** ** ****** ** *** **** *** IP ****** ***-*****-*******-****** ** ****** **** **** ** **** ** any **** ********** **** *** *****. *** ****** *** *** could ** *********** ** * ***** **** *** ****** *** be ** ***** ** ******* *** ********* ***** **** ** Hikvision ** **** ** **, * *** ******* ******** ** desperation. ** *** ********** ***** **** ******** ******** *** ******** as **** *** ** ******* ***** *****. *** **** *** concede **** ** ***** * ***** (* ******) **** ********* intent ** **** **** ********* ******* ** ******** ******* ** won't ****** ******* ******* ** ******* *** **** ******* ** not *** ********* ******.**** ** *** **** ******** **** *** folks **** **** ****, (***** * ****** ** **** **). If *** **** ********** ***** *** ****** ** ** *** the ***** ** *******, *****? ** ***** ** ** **** to **** *** *** ** **** "*" *******? **** ***** this ** * ******** ******* *****, ******* ** ** ** fodder.

***** *** * **** ** *** ***** **** ** **** ask.

******* ** *******, *** ** *** *** ** **** ********?

********* ***'* **** *****, ***** ***** *****.

*** *** **** **** ***** *** **** ****** ****** ** 5? ***'* **** *** ****? ****** ******* **** **** *** your **** ******? **** *** *** ****** **? **** *********, unprofessional, ******** ******** **** *** **** ***** ***** ****** ****** UM. ** ***** * *** **** ** **********, **** ** open ************ *** ***** ** ******** **** ****** ******* **********, what ***** ***?

*** ** *** *** ** **** ********?

** #***, * ********. * ***** ********* ***** ** ********. Marty ****** ********* **** ** ****** ** **** ********** **** others ***** ***** *** ******* ** *********'* ******** ********* ** a ******* *** ****** ** ****. ***? ******* ** ***** how ********** ****** ** ********** ***** ************* ** ** ** say ********* **** **** ** ***** ** *** ****** *** dangerous *** ********* ******** **.

** ***** * *** **** ** **********, **** ** **** conversation

** ****, *****, *** *** *********** **** ***** ** ****.

*****, **, ** *** **.

** ****** *******, ****** **** **** **** ** ******* ***** security ************** ** *** **** **** ***** **** ***** ****** makes. **** ***'* **** ****.

*** *** ****** ***** ****?

** *** *** ****** *********** ******* **** ****** *** *** VMS ***** ***'* ** ********* "*** ** *** ******" ******. That's *** ** **** ******* ****** ** *** ******** ******** TLS. *** *** **** ******* ** ********** *** **** **** week's ****-***** ****** *******.

* ***'* ********** *** *** ********* **** ****** ** ****** an ******* **** ** ** ********** **** **********. ***** ******** that *** ***** ** ***** *******, **** ** **** *** bad, *** ***** **** ********* ** ********* ** ****** **** a ******** *** ****** ********* ** *** ** *** ***. I ***** *** **** **** ** *** **** ****** *** I ****** ****** ********* ** ******* ** ******* ***. *** delay ** ********* ***-********* ** * ******** ***** ** ****** troubling.

**** ** **** *** **** ****** * **** ***** ***** Digital ******** ***** **** ** ********** ******* ***** ********. **** there *** *** ***** ** *** **** ****** ** ******** be ******** ** **. ** ***** ***** **** ******** *******, it ******* * *** ****. **********, ** * **** ********* in *** ****, * **** *** **** **** ******* ***** has **** **** ** ******* ** **** ** **** *** serious ******.

* ***** ******** ** *** *** ******* ********* *******, *** they ***** ******** **** *** ******** *** **** *** ********* on * ****** ****. *** ***** ******** *** ****** ********.

* **** *** **** * ***'* ***** *** ************ ******** cloud ******** ** *******. * **** ******* *** ** ** personal ********* ******* **** *** ****** ******. * ******* *** firmware *** *** ******** ****** **** *** ******** *** ***** enabled *****.

** ** ******* ** *** *** ***** **** ** **** Hikvision ***** ******** *** *** ***** **** *********'* **** ** security ***** *********** ********* *** **** **** **** ** **** a *** ** **** **** ***'* **** ******* ******** ********* and **** ***** ***'* ******** ***** ******** ** *** ********.

* ***** ******** **** *** *** ** ****** *********. ***** I ***** ********** ***** *** ********* ****** ** ******** * would ***** ** ** ****** ** ****** *** **** *** source ****** **** ******* *** ****** ***** ******* ** *** claims ** **** ********* *** *******. *** *** **** ****** have ***** *********** *** *** ****** ** ********, ******** **** company ***** ** ******** ** **** ***** ******* **** *** road. * ***** ***** **** ** ***** **** ***'* **** the ********* ** **** **** *** **** ** *********** ******* in ***** ** ******* *********. ***** ***** *** ********* **** who ***** ******* * ***** ** *** $**/****** ******* ***** the ****** ** ******* **** ***?

********** *******: ****** ***** ***** ***** ****** ** *** **** to ** *** **** - *** ******* *** ****** ***** have ** *** *** ****** *******. *** *** ***** ********** (almost *****) **** ** ** ** *** *** ***** **** would ************ ** ****** ************ **** *** ************ ** * result. **** ****** ***** ******** ****** *************** ** ***** ** remedied. **** ****'* ****** ***** ****** ******* ******* ***** *** drivers **** *** ******* ********, ******* *** **************.***, *** ******* became **********.

**** **** ****** ***** *******. ******* **** ** ***** **** their ******* ******* ** ********* *** *** **** ****** **** will **** ** **** *** **** ********** ********* ** ******* to *** ******* ***** ***** *****. ***'* ****** **** ***** defenders ** *** ***** ******** **** ** **** **** * seemingly ***** ****** **** ** ****. * ****** **** **** bought *** ***** ******** ** **** *****, ** ** **** cases * *** ******* **** ******* ** ** ****** ** by **** ************ ********** ***** *** **** ******* ****** *** their ********* ********. ******* *** ** **** **** *** **** they **** * ******* ***** *** * **** **** ******* when ** ***** ** ***** ******** ** *********. ******** **** some *********, ** ******** *** ** **********, ****** **** ** quotes *** *** ********* **** ***** *** *********** **** **** expensive ******** ** ******** *** ****** *** *******?

** ****** *** *** ********* **** ***** *** *********** **** more ********* ******** ** ******** *** ****** *** *******

**********:****** ****** *********.

** ********, ******, #**, *** *** **** *** ********* ********** that ******* ********** ** **** **** **** **** *********.

** *** ***** ****, * ** ***** **** *** ******* that **** ****-**** ********* *********** *** *** **. ** **** go **** *** *** "*** ** ********, * **** *** these ***** *** **** ******* **** *** **** *** ** have * ******** ** ** *** *** ************ ** * subsidiary ** *** ******* **********", **** **** * ******* ** scary ********.

**** ** *** **** '** ********' ****? *** ** **** relevant '** ********'? ** ****** ** **** **** ** ***** scenario ** ***** ****** ** ****** **** *** ***** ************ is **** ***** ****. ** ******* ***** ***'* ****** ***** on **** *** **** ******* ** **** ********** ****,**** ***** be * ****** ***** ** *** '****** ******' *****'** **?

*'* *** ** ********** ** *********, *** **** ****** **** friends *** * ****** ** *** ** ****** *** **** in ***** ****. ******* ***** *** ******* *** *******...

*'* **** ** ** * ******* **** *** **** ******* these ** ***-**** *** *-* *****.

*** *** **** ** **** ***** ********* **** **** **** selling **** ********* *** *-* ***** **** ****** *** ** around ** *-* **** ***** ** **** **** *** **** boxes ** **** *********. ** ************* ** ****** ***** **** to *** ******** **** ***** **** ** **** **** ***** cables *** **** * ****** *** ** *** *******

**** *** **** **** **** ******* **** **** ****** ********* those *** ****** **** ***** ***** ****** *** ****** * one **** **** *** ****** ** * ****.

Login to read this IPVM report.
Why do I need to log in?
IPVM conducts unique testing and research funded by member's payments enabling us to offer the most independent, accurate and in-depth information.

Most Recent Industry Reports

Security Installation Tools Guide - 22 Tools Listed on Feb 19, 2019
In this guide, we cover 22 tools that security installers frequently use. This is one part of our upcoming Video Surveillance...
Sales Cuts At Rasilient on Feb 19, 2019
Over the past 2 years, video surveillance storage specialist Rasilient has expanded its workforce significantly, aiming to build its own branded...
Exacq Raises VMS Software Pricing Twice in Less Than a Year on Feb 18, 2019
Most VMSes regularly release new features, but rarely increase their prices. For the 3rd time in 4 years, and 2nd time in 8 months, since being...
Axis IR Multi Imager Camera Tested (P3717-PLE) on Feb 18, 2019
Axis has released their first IR multi imager, the P3717-PLE, a repositionable model listing 360° IR illumination and flexible positioning,...
Ubiquiti Favorability Results 2019 on Feb 18, 2019
Ubiquiti has quietly grown into a $1+ billion annual revenue company, with offerings across wireless, wireline network and video surveillance (see...
Casino Surveillance Pro Interview: James Lathrop on Feb 15, 2019
James Lathrop has been working in casinos for almost 25 years. During that time, he says he has held "just about every job you can do in the...
Hikvision 2018 Revenue Tops $7 Billion USD But Growth Slows To Low on Feb 15, 2019
Hikvision's annual revenue topped $7 billion for the first time in 2018, although growth slowed sharply. In this post, we analyze the latest...
Hanwha Smaller Multi Imager Tested (PNM-9000VQ) on Feb 14, 2019
Hanwha's first repositionable multi imager PNM-9081VQ tested well, but was huge, over 12" wide and weighing in at over 10 pounds. Now, they have...
ADT And 'The Defenders' Silent About Massive Complaints on Feb 14, 2019
ADT's largest dealer, "The Defenders" has been the subject of a massive number of complaints over many years and many forums, most recently a CBS...
Hikvision Chairman Praises United Front on Feb 14, 2019
Hikvision’s controlling shareholder held a meeting last month praising the United Front, a Communist Party organization known for its secretive...

The world's leading video surveillance information source, IPVM provides the best reporting, testing and training for 10,000+ members globally. Dedicated to independent and objective information, we uniquely refuse any and all advertisements, sponsorship and consulting from manufacturers.

About | FAQ | Contact