CVE-2026-16843 PUBLISHED

Assigner: hikvision
Reserved: 24.07.2026 Published: 31.07.2026 Updated: 31.07.2026

Some Hikvision Wireless Access Points are vulnerable to authenticated command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 7.2

Product Status

Vendor Hikvision
Product DS-3WAP521-SI
Versions
  • Version V1.1.6601 build251223 and earlier is affected
Vendor Hikvision
Product DS-3WAP522-SI
Versions
  • Version V1.1.6601 build251223 and earlier is affected
Vendor Hikvision
Product DS-3WAP621E-SI
Versions
  • Version V1.1.6601 build251223 and earlier is affected
Vendor Hikvision
Product DS-3WAP622E-SI
Versions
  • Version V1.1.6601 build251223 and earlier is affected
Vendor Hikvision
Product DS-3WAP623E-SI
Versions
  • Version V1.1.6601 build251223 and earlier is affected
Vendor Hikvision
Product DS-3WAP622G-SI
Versions
  • Version V1.1.6601 build251223 and earlier is affected
Vendor Hikvision
Product DS-3WG105G-SI
Versions
  • Version V1.1.6601 build251223 and earlier is affected
Vendor Hikvision
Product DS-3WG105GP-SI
Versions
  • Version V1.1.6601 build251223 and earlier is affected
Vendor Hikvision
Product DS-3WG210GP-SI
Versions
  • Version V1.1.6601 build251223 and earlier is affected
Vendor Hikvision
Product DS-3WG507G-SI
Versions
  • Version V1.1.6601 build251223 and earlier is affected

Credits

  • independent security researcher exzettabyte finder

References