CVE-2025-66174: Medium severity Hikvision Ds-7104hghi-f1 Firmware vulnerability
There is an improper authentication vulnerability in some Hikvision DVR products. Due to the improper implementation of authentication for the serial port, an attacker with physical access could exploit this vulnerability by connecting to the affected products and run a series of commands.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66174?
CVE-2025-66174 is considered a high severity vulnerability due to the potential for unauthorized access via the serial port.
How do I fix CVE-2025-66174?
To mitigate CVE-2025-66174, ensure that firmware is updated to the latest version provided by Hikvision that addresses this vulnerability.
Which Hikvision products are affected by CVE-2025-66174?
CVE-2025-66174 affects Hikvision DVR models DS-7104HGHI-F1 and DS-7204HGHI-F1 with specific firmware versions.
Who can exploit CVE-2025-66174?
An attacker with physical access to the affected Hikvision devices can exploit CVE-2025-66174 to execute unauthorized commands.
What type of vulnerability is CVE-2025-66174?
CVE-2025-66174 is categorized as an improper authentication vulnerability.