CVE-2022-28173: Critical severity hikvision ds-3wf0ac-2nt vulnerability
The web server of some Hikvision wireless bridge products have an access control vulnerability which can be used to obtain the admin permission. The attacker can exploit the vulnerability by sending crafted messages to the affected devices.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-28173?
CVE-2022-28173 is a vulnerability that affects the web server of some Hikvision wireless bridge products, allowing an attacker to obtain admin permission.
How can an attacker exploit CVE-2022-28173?
An attacker can exploit CVE-2022-28173 by sending crafted messages to the affected devices.
What is the severity of CVE-2022-28173?
CVE-2022-28173 has a severity rating of 9.8, which is considered critical.
Which Hikvision wireless bridge products are affected by CVE-2022-28173?
Some Hikvision wireless bridge products, including the Hikvision Ds-3wf0ac-2nt Firmware up to version 1.1.0 and the Hikvision Ds-3wf01c-2n/o Firmware up to version 1.0.4, are affected by CVE-2022-28173.
How can I fix CVE-2022-28173?
To fix CVE-2022-28173, it is recommended to refer to the security advisory provided by Hikvision at the given reference link.