CVE-2025-66176: Buffer Overflow

Published Jan 13, 2026
·
Updated

There is a Buffer overflow Vulnerability in the device Search and Discovery feature of Hikvision Access Control Products. If exploited, an attacker on the same local area network (LAN) could cause the device to malfunction by sending specially crafted packets to an unpatched device.

Affected Software

57 affected components
Hikvision Access Control Products
All of the following
Hikvision Ds-k1t331 Firmware<3.7.80
Hikvision Ds-k1t331
All of the following
Hikvision Ds-k1t341a Firmware<3.7.80
Hikvision Ds-k1t341a
All of the following
Hikvision Ds-k1t341b Firmware<3.7.80
Hikvision Ds-k1t341b
All of the following
Hikvision Ds-k1t671 Firmware<3.7.80
Hikvision Ds-k1t671
All of the following
Hikvision Ds-k5671 Firmware<3.7.80
Hikvision Ds-k5671
All of the following
Hikvision Ds-k1t672 Firmware<3.7.80
Hikvision Ds-k1t672
All of the following
Hikvision Ds-k1t680 Firmware<3.7.80
Hikvision Ds-k1t680
All of the following
Hikvision Ds-k1t981 Firmware<3.7.80
Hikvision Ds-k1t981
All of the following
Hikvision Ds-k1t341c Firmware<3.3.180
Hikvision Ds-k1t341c
All of the following
Hikvision Ds-k1t670 Firmware<4.48.0
Hikvision Ds-k1t670
All of the following
Hikvision Ds-k1t673 Firmware<4.48.0
Hikvision Ds-k1t673
All of the following
Hikvision Ds-k1t8003 Firmware<=1.4.21
Hikvision Ds-k1t8003
All of the following
Hikvision Ds-k1t804a Firmware<1.4.22
Hikvision Ds-k1t804a
All of the following
Hikvision Ds-k1t804b Firmware<1.4.23
Hikvision Ds-k1t804b
All of the following
Hikvision Ds-k1t201a Firmware<1.3.65
Hikvision Ds-k1t201a
All of the following
Hikvision Ds-k1t105a Firmware<1.3.65
Hikvision Ds-k1t105a
All of the following
Hikvision Ds-k1t342 Firmware<4.48.0
Hikvision Ds-k1t342
All of the following
Hikvision Ds-k1t343 Firmware<4.48.0
Hikvision Ds-k1t343
All of the following
Hikvision Ds-k1t344 Firmware<4.48.0
Hikvision Ds-k1t344
All of the following
Hikvision Ds-k1t6qt-f72 Firmware<4.48.0
Hikvision Ds-k1t6qt-f72
All of the following
Hikvision Ds-k1t6qt-f43 Firmware<4.48.0
Hikvision Ds-k1t6qt-f43
All of the following
Hikvision Ds-k1t8005 Firmware<3.25.40
Hikvision Ds-k1t8005
All of the following
Hikvision Ds-k1t808 Firmware<3.25.40
Hikvision Ds-k1t808
All of the following
Hikvision Ds-k1t320 Firmware<3.9.40
Hikvision Ds-k1t320
All of the following
Hikvision Ds-k1t321 Firmware<3.9.40
Hikvision Ds-k1t321
All of the following
Hikvision Ds-k1t323 Firmware<4.23.41
Hikvision Ds-k1t323
All of the following
Hikvision Ds-k1t510 Firmware<4.23.41
Hikvision Ds-k1t510
All of the following
Hikvision Ds-k5033 Firmware<4.37.40
Hikvision Ds-k5033

Event History

Jan 13, 2026
CVE Published
via MITRE·01:47 AM
Data Sourced
via MITRE·01:47 AM
DescriptionSeverity
Data Sourced
via NVD·03:16 AM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-66176?

The severity of CVE-2025-66176 is classified as critical due to potential device malfunction from exploitation.

2

How do I fix CVE-2025-66176?

To fix CVE-2025-66176, update your Hikvision Access Control Products to the latest patched version provided by the manufacturer.

3

Who is affected by CVE-2025-66176?

CVE-2025-66176 affects users of Hikvision Access Control Products that have not been updated to mitigate the stack overflow vulnerability.

4

What type of vulnerability is CVE-2025-66176?

CVE-2025-66176 is a stack overflow vulnerability that can be triggered by sending specially crafted packets to the affected device.

5

Can CVE-2025-66176 be exploited remotely?

CVE-2025-66176 requires an attacker to be on the same local area network (LAN) as the targeted Hikvision device to exploit the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203