CVE-2025-66174
MEDIUMDescription
There is an improper authentication vulnerability in some Hikvision DVR products. Due to the improper implementation of authentication for the serial port, an attacker with physical access could exploit this vulnerability by connecting to the affected products and run a series of commands.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| hikvision | ds-7104hghi-f1_firmware |
| hikvision | ds-7104hghi-f1 |
| hikvision | ds-7204hghi-f1_firmware |
| hikvision | ds-7204hghi-f1 |
References
Frequently Asked Questions
What is CVE-2025-66174? +
How severe is CVE-2025-66174? +
What products are affected by CVE-2025-66174? +
How do I check if I'm vulnerable to CVE-2025-66174? +
Related Vulnerabilities
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
Kavita is a cross platform reading server. Prior to 0.9.0.2, an Improper Token validation flaw permits a remote and unauthenticated …
IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19
OpenLearnX is an open-source, decentralized learning and assessment platform. Prior to 2.0.4, a critical authentication vulnerability was identified in OpenLearnX …
PAM-PKCS#11 is a Linux-PAM login module that allows a X.509 certificate based user login. Prior to version 0.6.13, if cert_policy …