Hikvision Vulnerability Permits Wi-Fi Attack

Author: Brian Karas, Published on Nov 28, 2017

Hikvision acknowledged a Wi-Fi cyber security vulnerability on November 27, 2017. No special passwords, text strings, or programming knowledge are required. Any attacker within Wi-Fi range of the impacted cameras can exploit this.

IPVM spoke with the researcher who discovered and reported this vulnerability. We examine the limitations, exploit potential, affected products, and Hikvision's problems in responding to the vulnerability.

********* ************* **-** ***** ******** *************** ******** **, ****. ** ******* *********, **** *******, ** programming ********* *** ********. *** ******** ****** **-** ***** ** the ******** ******* *** ******* ****.

**** ***** **** *** ********** *** ********** *** ******** **** vulnerability. ** ******* *** ***********, ******* *********, ******** ********, *** Hikvision's ******** ** ********** ** *** *************.

[***************]

Limited ****** *********

**** ************* ** ******* ** **-** ******* ***** *** **** has *** ********** **-** ********, ********** *** ******** *******. **** limits ** ** * ********** ***** ****** ** ********** *****, as **-** *******, ** ******* *** *** **** *******, *** those ***** **-** ******* *** ****** ** ********* **-**.

Exploit ********

*** ************* ** **** ***** ******* *** ***, ** *******, to ******* * ******** ******* ****** "*******", **** ** ********. An ******** *** ****** * **** ******* **** **** "*******" and * ********** ******* **** ************* ******* ** **, ******** the ******** ** ******* ** *** ******. ********* ** *** researcher, *** ********** ****** **** ** ****** **** * ** DaVinci ******* *** ** ******** **** **** ** ****** *** origin ** *** *************.

********* ****** **** *** ********* ***** *** ********:

**-**********-***, **-**********-***, **-**********-**, **-**********-**, **-********-***, **-********-***, **-*******-**, **-********-**

*** ********* ******* ***** ** ******* ** *** ** ******** can *** *** **-** ******* ****** **** ******* ******** ** a *** ** **** ****** ** ** ******** *******:

Firewalls ***********

******* *** ******** ******** **** *** ****** **-** ******* ********* on *** ******, *** ******** ********, ****, ** ***** ******* used ** ****** ******** *********** ** *** ******** **** ** the ******* ***** *** ** ******* ** *** **-** **** of *** ******, ******* ** **** ** ******.

Exploit *********

********** ** *** ********** (**** ******) ** *********, **** ** ***** ***** ******* **** ******** **** **** prevents ********* *** **-** ********* **** *** ***** **** (** to *.*.*), *** **** *** ********** ** ************ ******** *******, ****** *** ******* ********* **** **** *** ***** ** these ******* **** ******* **-** ********.

*** *********** *** *** ******** ** ** ** **-** ***** of *** ****, *** **** *** **** **** **** ******* Wi-Fi ********, ***** **** ************* **** ****** *************'* ******** *************. ** **, *******, * *********** ********* ** *********'* **** to **** ******** **** **** ******* ********.

Hikvision ***** ******** ******* ************

***** ********* ********** *********** ** ****** ***************, *** *** * specific ***** ******* *** ***** *******, ******** **** ******:

*** ********** ******* **** ******* ********* *********'* ********, ** **** 4 ******, *** ******** ******* ******** ** *** * ******** to **** **********, ***** ** **** ** *** ************* ********** post:

***** ******* ******* ******** **** ***** ********* *** ********* ******* He *** ******** ******************'* ***** ******** *******, ********* ****** ******** ******** *** ******** *********** *******, ***** ****** **** ********** **** ***** ************* ** ***** own. ************,*********'* ***** *** **** ** ***** *********** **** *** *******, ******* *** **** ** ************* **** open ****** *** ******* ******* ********.

Positive ******** **** ***** *****

*** ********** ****** **** *** ******** **** ********* ********** **** from *** ***** ******** ********* *****, **** ** ***** ** ** ******* *** ******** ********** in ********** *** *********. ** **** ***** *** * **** hire *** *********, *** ***** ********* ** **** ** ******* Hikvision's ******* ***** ******** ************** *** ************* ********** ******* *********** such ** ***** ******** ************** ******** *******.

Hikvision ** ********* ************ ** *****

******* ************* *** ****** ** ******* ***, *** ****** ******* firmware *********, ** **** ** *********** *********** ** ***** **** vulnerability, ********* *** *** ********* ****** ***** ****** *** ************* was ********* ******** ** **** **********.

Special ******** ****** ***

********* *** *** ******* ** ****'* ******* *** ********** ****** on *** ************* **********. *******, **** **** * ***** ***** our ***** ** *********, *** ******* ******** * "******* ********", reusing *** ******* **** *** ***** **** **** ***** ******* Bulletin ******** * ***** *** ** ******* ****** ******* ********* *************.:

~** ******* *****, ********* **-**** *** ******** **** * ********* subject **** *** *****:

** *** ********, ******* ** ********** ******* ** *** ************* first, ********* ****** ** ******* ***** **** ****** ******* ****** features, ****** **** *** *********** ********** **** *** ******** ********* on **** ** *** ******** *****.

** ******** ******** ******(***) ********* **** ********, ***** *** ******* ** ** ** "Information ****" ********, **** ** ****** ********:

***, *** *** ******* ******** ******, ************ ******** ****** ******** and/or ********* **-** (*** ***** **** ******** *** ****** ** support ****).

***** *** "****** ********" ******* ***** ************* ** * ***** error, *********'* ****** ** ********* *** ************* ******** *** ******* rushed ** ***** ***** ********* **** **** ****** ***** **** the ************* ***** ** ******** *********, *** ******** **. *** Hikvision **** ********** ** ***** *** ************* ********* ***** *******, and *** * ************* ******** *** ************ ******* ** *****, they ***** **** *** ***** ****** ** ******* "********* *** outreach" ******* ** ******* ** ******* ** *** ********** *** issuing *******-******** *************.

Continued ********* *********** ******

**** ************* ** ** ********* *****, **** ****** ** ********** in ******** *********** ********* ** ******** ***** ******** *****. *********,*********'* ****** *********** ******** ** *******,***** ****** *************, ****** ******** ******** *************, ***** ******, *** **** ***** ** *************** **** **** been *** ****** ** **** ******** ****** ** **************, ** choices **** ** *** ******* ** ************ ***** ******** ******** to ***** ******* ** *** ********.

Communication ************ ******

********* ***** **** ****** ************* **** *******, **** ********* *** less ********* ************* ** ***************.

Comments (15)

** *** ****** *** ********* **** *** **-*******-***/* *** *** DS-2DE3304W-DE ****** ******** (*** ***** ******* ** ******) ******* ****** a ****** ********. *** **** ** **** ** ******* ** the **** *************.

********* **** *** **** ******** ******* ** ***** **** ****** (xx3304xx *** ******), ** *** ******* (*** ****** ****) ** on ***** ********** *** ****. **** ******* *****'* ****, **** just ***** *** ** *** **** ****** ***** **** *** have *** ****** ******. *** *** **** *** ****** **** doesn't ****.

*** *** ********* ****** ** ** ******* *** ***** **** hacking **** **** ** *** **** **** ** ********??

**** ** ********** ******.

***** -

**** *** *** ********** ****** **** *** ******* *** ***** hit ** ************ ******** *******, ***** ****** ******* ** ****** ** ****** ****** ******** regardless ** *** ***** ******** ********/**********. *********, **** **** ********, Hikvision ******** * *** *** ********* ** ********** ****** *********.

*** **** *** *****, *** *** *** *****. ** ******** I *** **** *** ************ ******* ***** ***** *** ****** thousands ** ******* **** **** *** *** **** ******* ** "HACKED". ****, ***** *** **'* ** ********* ** ******* **** this ************* ********* ** *** ********. * **** *** ********** how/why *** **** **** *** ***** ****** ** **** "******" are ******** ******** ** *** ****** ***** ******* ****** ** vulnerable *******.

**** ** * *** ** ***** * **** ******* ****** 1,000 ******* (***** ** *** ** ******, ** **** ****** could ** ***) ******* "******" *** *** ****** ****. *** can *** **** *** ******* ************ ** *** **, *** Europe:

********: ** **** ********* ****** **** *** **** *** ***** is ********* *** ** *** ***** ****** ***** (*.*. **** have *** **** ******* ********* ** ***** **** ******** ****), how **** *** *** ********** ******* ****** ** ** ** N ******* *** ******?

***** *** *** **** ********** *******, **** *** ********** ******* that **** **** ****** ** ******* *** *******-******** **** "******" (or "******", ** ****-*********** ********).

***** *** ** ******* ** ***** **** ******* *** ******* equivalent ** "******", *** ** ***** *** *** ******* *** alternate *********/*********, ***.

**** ***** *****... : )

*** ** *** ** ********* ****, ** *** *****?

******* ****** *** **** **** *** ********* ******* ** ***** database, ** *** ** * *** ****.

**** **** ********************? ** ***** *******?

** ***** **... ** *** ****** ******* *** ******* ***'* show ** ** **** ****** *** ******* ********* ** ****** (when ***** *** **** ** **** ***** **** ********) ** because **** ****** *** ******* ** *** ******* ******* ** the **** ******, **** *** *** ***** *** **** ****** devices ******* ** ** *********? ***** * ***** ****** **** of ***** ******* **** ***** ** *******?

*** *** ***** *** **** ****** ******* ******* ** ** Australia?

******* *** ****** ******** *** **** *** *** *** ********* cameras ** *********. * ** *** **** ** **** ** because ********* *** *** ****** *********** *****, ******* ****** ****** does *** **** *** ** *********, ** *********** **** ****** firewalls, ** ********* ****.

** *** *** *** *** ** ******, ***** ** ***** I **** ***** ** ******** ********** ******* ****, **** * can *** **** ****.

** *****,

*** ********* ** *********** *** *** ***.

***** *** *** **** ******* **** ******* *** *** ******?

**,

*******

**** *** ** ******* ******** **** *** ***** ******* *** a **** ****, ** *** ***** “*” *** *** ** get *** **** ******* “*”. *** ****** **** ***** “***”.

* **** **** **** ********* *** ********* ***** **** *** audio ***** ******* *** **** ******* ********.

******* ********* **** !!! **** * *****.

******: * *** ***** **** ********** ********* *** *** ****** that *********** ****** ** ****** *** ********:

** ******** ******** ******(***) ********* **** ********, ***** *** ******* ** ** ** "Information ****" ********, **** ** ****** ********:

***, *** *** ******* ******** ******, ************ ******** ****** ******** and/or ********* **-** (*** ***** **** ******** *** ****** ** support ****).

***************** * ********* ******:

*** ****** ********* ***** ***** ******* ******* *** **** ******* when ***'** ******* ** ** ** *** **** *** ****?

*** ************ ** *********.

Login to read this IPVM report.
Why do I need to log in?
IPVM conducts unique testing and research funded by member's payments enabling us to offer the most independent, accurate and in-depth information.

Related Reports on VMS

Massive Leak Of Chinese VMS Provider Exposes Xinjiang Surveillance on Feb 20, 2019
A subsidiary of China’s claimed largest VMS provider is tracking the precise location and ethnicity of millions in China’s Xinjiang region,...
Exacq Raises VMS Software Pricing Twice in Less Than a Year on Feb 18, 2019
Most VMSes regularly release new features, but rarely increase their prices. For the 3rd time in 4 years, and 2nd time in 8 months, since being...
Axis IR Multi Imager Camera Tested (P3717-PLE) on Feb 18, 2019
Axis has released their first IR multi imager, the P3717-PLE, a repositionable model listing 360° IR illumination and flexible positioning,...
Casino Surveillance Pro Interview: James Lathrop on Feb 15, 2019
James Lathrop has been working in casinos for almost 25 years. During that time, he says he has held "just about every job you can do in the...
Cisco Meraki Cloud VMS/Cameras Tested on Feb 13, 2019
Cisco Meraki says their cameras "bring Meraki magic to the enterprise video security world". According to Meraki, their magic is their management...
Solink Raises $12 Million - Company Profile on Feb 12, 2019
Most industry professionals have never heard of Solink, a company whose tagline is: It's time to revolutionize the way business uses...
Milestone Drops Hikvision From Elite Partners on Feb 11, 2019
Milestone has quietly dropped Hikvision from their 'Elite Partners', less than 3 years after adding the Chinese government-owned...
FLIR Favorability Results 2019 on Feb 08, 2019
FLIR has had a challenging past few years including FLIR Security business struggling, FLIR restructuring their security division and FLIR selling...
No Genetec Major Releases In Over A Year on Feb 06, 2019
Annual VMS licenses are a controversial practice in the video surveillance industry, with many questioning their need or value. However, enterprise...
PlateSmart LPR Profile on Jan 31, 2019
PlateSmart Technologies claims to "turn any conventional surveillance camera into a license plate recognition camera" We spoke with PlateSmart to...

Most Recent Industry Reports

Outdoor Camera Mounting Hardware Guide on Feb 21, 2019
Mounting cameras outdoors can be challenging, requiring understanding different types of equipment and methods. In this guide, we teach this...
HID Favorability Results 2019 on Feb 21, 2019
HID favorability results were strong, in the 2019 IPVM integrator study of 200+ integrators, with a net +62% and low negativity as the table below...
First US State, Vermont, Bans Dahua and Hikvision on Feb 21, 2019
The first US state, Vermont, has issued a ban on a number of Chinese and Russian manufacturers including the world's 2 largest video surveillance...
ADI 'SAVE BIG' On FLIR And Hikvision Examined on Feb 20, 2019
One is a major US defense supplier. The other is owned by the Chinese government. But you can "SAVE BIG" on both at ADI. In this note, we...
BluB0x Company Profile on Feb 20, 2019
BluB0x has doubled in revenue every year since its founding in 2013, according to CEO Patrick Barry. We originally reported on them in 2015. At the...
Security Installation Tools Guide - 22 Tools Listed on Feb 19, 2019
In this guide, we cover 22 tools that security installers frequently use. This is one part of our upcoming Video Surveillance...
Sales Cuts At Rasilient on Feb 19, 2019
Over the past 2 years, video surveillance storage specialist Rasilient has expanded its workforce significantly, aiming to build its own branded...
Exacq Raises VMS Software Pricing Twice in Less Than a Year on Feb 18, 2019
Most VMSes regularly release new features, but rarely increase their prices. For the 3rd time in 4 years, and 2nd time in 8 months, since being...
Axis IR Multi Imager Camera Tested (P3717-PLE) on Feb 18, 2019
Axis has released their first IR multi imager, the P3717-PLE, a repositionable model listing 360° IR illumination and flexible positioning,...

The world's leading video surveillance information source, IPVM provides the best reporting, testing and training for 10,000+ members globally. Dedicated to independent and objective information, we uniquely refuse any and all advertisements, sponsorship and consulting from manufacturers.

About | FAQ | Contact