National CSIRT-CY | National Computer Security Incident Response Team of Cyprus

Η Εθνική Ομάδα Αντιμετώπισης Ηλεκτρονικών Επιθέσεων προβλέπει την αύξηση της ηλεκτρονικής ασφαλείας ενισχύοντας την προστασία του κυβερνοχώρου των Εθνικών Κρίσιμων Πληροφοριακών Υποδομών, των τραπεζών και των παροχών επικοινωνίας της Κυπριακής Δημοκρατίας.

Command Execution Vulnerability in Hikvision Switch Products

19 Μαΐου 2026

The Digital Security Authority (DSA) wants to bring to your attention regarding a vulnerability affecting Hikvision Switch Products.

 

Executive Summary: 

The Digital Security Authority (DSA) has observed Hikvision has disclosed a high-severity authenticated remote command execution vulnerability affecting several discontinued smart switch products.

 

Technical Details

Hikvision has disclosed a high-severity authenticated remote command execution vulnerability affecting several discontinued smart switch products. The flaw arises from insufficient input validation mechanisms within the device firmware, enabling authenticated attackers to inject and execute arbitrary operating system commands remotely.

 

Vulnerability Details

CVE ID: CVE-2026-3828
• CVSS v3.1 Score: 7.2 (High) (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)
Impact: Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution.

 

Affected products

 

Recommendations

The Digital Security Authority (DSA) recommends immediately upgrading all affected devices to the latest fixed firmware versions immediately.


Please ensure to distribute this information among your subsidiaries and partners and provide us with any pertinent information or findings you may have (such as Indicators of Compromise, Tactics, Techniques, and Procedures, etc.).


The Digital Security Authority (DSA) extends its appreciation for the continued collaboration.

 

References

    1. https://www.hikvision.com/en/support/cybersecurity/security-advisory/command-execution-vulnerability-in-some-hikvision-switch-product/

 

Disclaimer

The information presented in this report is based on available data up to the 11th of May 2026. 

 

 [ Get the report  in .PDF ]

 

Working towards a trusted and cyber secure Europe

Protect your cyber hygiene

Cyber Europe 2022 [exercise]

Cyber threats require heightened defences