Command Execution Vulnerability in Hikvision Wireless Access Points
CVE-2026-0709
7.2HIGH
What is CVE-2026-0709?
Certain Hikvision Wireless Access Points are susceptible to an authenticated command execution vulnerability due to inadequate input validation. This loophole permits attackers with valid credentials to exploit the flaw by transmitting specially crafted packets containing harmful commands to the affected devices. As a result, this may enable arbitrary command execution, posing a significant risk to device integrity and security.
Affected Version(s)
DS-3WAP521-SI V1.1.6303 build250812 and earlier
DS-3WAP522-SI V1.1.6303 build250812 and earlier
DS-3WAP621E-SI V1.1.6303 build250812 and earlier
