Command Execution Vulnerability in Hikvision Wireless Access Points
CVE-2026-0709

7.2HIGH

Key Information:

Vendor

Hikvision

Vendor
CVE Published:
30 January 2026

What is CVE-2026-0709?

Certain Hikvision Wireless Access Points are susceptible to an authenticated command execution vulnerability due to inadequate input validation. This loophole permits attackers with valid credentials to exploit the flaw by transmitting specially crafted packets containing harmful commands to the affected devices. As a result, this may enable arbitrary command execution, posing a significant risk to device integrity and security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

DS-3WAP521-SI V1.1.6303 build250812 and earlier

DS-3WAP522-SI V1.1.6303 build250812 and earlier

DS-3WAP621E-SI V1.1.6303 build250812 and earlier

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

exzettabyte
.