Privilege Escalation Vulnerability in Hikvision DVR Products
CVE-2025-66173
What is CVE-2025-66173?
A privilege escalation vulnerability exists in certain Hikvision DVR products due to inadequate authentication for the serial port interface. This flaw enables an attacker with physical access to exploit the vulnerability by connecting to the device, thus gaining entry to an unrestricted shell environment. Such access can lead to unauthorized control and potentially compromise the integrity and confidentiality of the system.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
DS-7104HGHI-F1 Versions below V4.30.122_201107 (including V4.30.122_201107)
DS-7204HGHI-F1 Versions below V4.30.122_201107 (including V4.30.122_201107)
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
