6.5
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Description
There is an improper authentication vulnerability in some Hikvision DVR products. Due to the improper implementation of authentication for the serial port, an attacker with physical access could exploit this vulnerability by connecting to the affected products and run a series of commands.
Basic Information
ID
CVE-2025-66174
Source
hikvision
Published
Dec 19, 2025 at 06:39
Modified
Dec 19, 2025 at 06:45
Affected Product
Vendor
Hikvision
Product
DS-7104HGHI-F1
Version
Versions below V4.30.122_201107 (including V4.30.122_201107)
Affected Versions
Hikvision DS-7104HGHI-F1 Versions below V4.30.122_201107 (including V4.30.122_201107)
Hikvision DS-7204HGHI-F1 Versions below V4.30.122_201107 (including V4.30.122_201107)
Hikvision DS-7204HGHI-F1 Versions below V4.30.122_201107 (including V4.30.122_201107)