CVE-2025-66173: Medium severity Hikvision DVR vulnerability
There is a privilege escalation vulnerability in some Hikvision DVR products. Due to the improper implementation of authentication for the serial port, an attacker with physical access could exploit this vulnerability by connecting to the affected products and gaining access to an unrestricted shell environment.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66173?
CVE-2025-66173 is classified as a moderate severity privilege escalation vulnerability.
How do I fix CVE-2025-66173?
To mitigate CVE-2025-66173, it is recommended to update the firmware of the affected Hikvision DVR products to the latest version.
What impact does CVE-2025-66173 have on Hikvision DVR users?
CVE-2025-66173 allows an attacker with physical access to gain administrative access to the device, potentially compromising sensitive information.
Which Hikvision products are affected by CVE-2025-66173?
CVE-2025-66173 affects specific models of Hikvision DVR products with improper authentication for the serial port.
Can CVE-2025-66173 be exploited remotely?
No, CVE-2025-66173 requires physical access to the affected Hikvision DVR devices for exploitation.