8.8

CVE-2025-66176

There is a Stack overflow Vulnerability in the device Search and Discovery feature of Hikvision Access Control Products. If exploited, an attacker on the same local area network (LAN) could cause the device to malfunction by sending specially crafted packets to an unpatched device.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
HikvisionDs-k1t331 Firmware Version < 3.7.80
   HikvisionDs-k1t331 Version-
HikvisionDs-k1t341a Firmware Version < 3.7.80
   HikvisionDs-k1t341a Version-
HikvisionDs-k1t341b Firmware Version < 3.7.80
   HikvisionDs-k1t341b Version-
HikvisionDs-k1t671 Firmware Version < 3.7.80
   HikvisionDs-k1t671 Version-
HikvisionDs-k5671 Firmware Version < 3.7.80
   HikvisionDs-k5671 Version-
HikvisionDs-k1t672 Firmware Version < 3.7.80
   HikvisionDs-k1t672 Version-
HikvisionDs-k1t680 Firmware Version < 3.7.80
   HikvisionDs-k1t680 Version-
HikvisionDs-k1t981 Firmware Version < 3.7.80
   HikvisionDs-k1t981 Version-
HikvisionDs-k1t341c Firmware Version < 3.3.180
   HikvisionDs-k1t341c Version-
HikvisionDs-k1t670 Firmware Version < 4.48.0
   HikvisionDs-k1t670 Version-
HikvisionDs-k1t673 Firmware Version < 4.48.0
   HikvisionDs-k1t673 Version-
HikvisionDs-k1t8003 Firmware Version <= 1.4.21
   HikvisionDs-k1t8003 Version-
HikvisionDs-k1t804a Firmware Version < 1.4.22
   HikvisionDs-k1t804a Version-
HikvisionDs-k1t804b Firmware Version < 1.4.23
   HikvisionDs-k1t804b Version-
HikvisionDs-k1t201a Firmware Version < 1.3.65
   HikvisionDs-k1t201a Version-
HikvisionDs-k1t105a Firmware Version < 1.3.65
   HikvisionDs-k1t105a Version-
HikvisionDs-k1t342 Firmware Version < 4.48.0
   HikvisionDs-k1t342 Version-
HikvisionDs-k1t343 Firmware Version < 4.48.0
   HikvisionDs-k1t343 Version-
HikvisionDs-k1t344 Firmware Version < 4.48.0
   HikvisionDs-k1t344 Version-
HikvisionDs-k1t6qt-f72 Firmware Version < 4.48.0
   HikvisionDs-k1t6qt-f72 Version-
HikvisionDs-k1t6qt-f43 Firmware Version < 4.48.0
   HikvisionDs-k1t6qt-f43 Version-
HikvisionDs-k1t8005 Firmware Version < 3.25.40
   HikvisionDs-k1t8005 Version-
HikvisionDs-k1t808 Firmware Version < 3.25.40
   HikvisionDs-k1t808 Version-
HikvisionDs-k1t320 Firmware Version < 3.9.40
   HikvisionDs-k1t320 Version-
HikvisionDs-k1t321 Firmware Version < 3.9.40
   HikvisionDs-k1t321 Version-
HikvisionDs-k1t323 Firmware Version < 4.23.41
   HikvisionDs-k1t323 Version-
HikvisionDs-k1t510 Firmware Version < 4.23.41
   HikvisionDs-k1t510 Version-
HikvisionDs-k5033 Firmware Version < 4.37.40
   HikvisionDs-k5033 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.01% 0.01
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
hsrc@hikvision.com 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-121 Stack-based Buffer Overflow

A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).