CVE 6.2 MEDIUM

CVE-2025-66173_CVE-2025-66173

6.2 / 10
MEDIUM
CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Description

There is a privilege escalation vulnerability in some Hikvision DVR products. Due to the improper implementation of authentication for the serial port, an attacker with physical access could exploit this vulnerability by connecting to the affected products and gaining access to an unrestricted shell environment.

Basic Information

ID CVE-2025-66173
Source hikvision
Published Dec 19, 2025 at 06:39
Modified Dec 19, 2025 at 06:45

Affected Product

Vendor Hikvision
Product DS-7104HGHI-F1
Version Versions below V4.30.122_201107 (including V4.30.122_201107)
Affected Versions Hikvision DS-7104HGHI-F1 Versions below V4.30.122_201107 (including V4.30.122_201107)
Hikvision DS-7204HGHI-F1 Versions below V4.30.122_201107 (including V4.30.122_201107)

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.