CVE-2026-3828: Input Validation
Some Hikvision switch products (discontinued since December 2023) are vulnerable to authenticated remote command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3828?
The severity of CVE-2026-3828 is classified as high due to the potential for remote command execution.
How do I fix CVE-2026-3828?
To fix CVE-2026-3828, it is recommended to upgrade to the latest firmware version provided by Hikvision or to disable affected features if an update is not available.
Who is affected by CVE-2026-3828?
CVE-2026-3828 affects users with certain Hikvision switch products that are vulnerable to authenticated remote command execution.
What type of attack can be executed using CVE-2026-3828?
Attackers can execute remote command injection attacks using CVE-2026-3828 if they possess valid credentials.
When was the vulnerability in CVE-2026-3828 disclosed?
CVE-2026-3828 was disclosed in December 2023.