CPATH-2026-0029 · General IoT

Hikvision IP camera / NVR unauthenticated command injection (CVE-2021-36260)

Two or more co-dominant consequence paths connect the public security record to a provisional EMERGENCY consequence band.

Candidate bandEMERGENCY
Co-dominant pathsPerception-to-action + Account authority + Fleet control plane

These paths are co-dominant because each reaches the record's highest candidate band, EMERGENCY; no array-order tie-break is applied.

Causal model

What has to happen for this consequence to hold?

3 candidate paths · explicit source, inference, and assumption boundaries.

Perception · Co-dominant path

Perception-to-action

Root access exposes live and stored surveillance video and can change the visual evidence that guards or operators rely on.

EMERGENCY
  1. accessSource-backed

    Network-reachable without prior access

    The vulnerable camera web service was reachable over the network, including on internet-exposed installations, without a prior account.

    EvidenceNVD

  2. boundaryModel inference

    Cross-domain authority chain

    The request crosses from the network into the camera operating system and then into the human security decisions driven by its feed.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Safety-driving perception or intimate data

    Root access exposes live and stored surveillance video and can change the visual evidence that guards or operators rely on.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Perception-to-action

    Root access exposes live and stored surveillance video and can change the visual evidence that guards or operators rely on.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Coordinated operational recovery

    Recovery requires patched firmware, verification that persistence was removed, and reset or credential rotation where compromise is suspected.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 4
Network-reachable without prior access

The vulnerable camera web service was reachable over the network, including on internet-exposed installations, without a prior account.

Source-backedNVD
Execution complexityEC 4
Straightforward operation

A public exploit can inject a command through one unauthenticated HTTP request; no memory-corruption chain is required.

Source-backedNVD
ExposureEX 4
Reach and effort support the same exposure

The documented reach and required effort are equally permissive, so neither reduces the other.

Model inference
Consequence
Physical / safetyPH 3
Credible safety consequence

Suppressing or fabricating a security-camera feed can hide activity from operators and reduce the physical-security margin of the monitored site.

Model inference
Data / perceptionDP 4
Safety-driving perception or intimate data

Root access exposes live and stored surveillance video and can change the visual evidence that guards or operators rely on.

Model inference
AuthorityAT 3
Administrative or command authority

Command injection reaches operating-system control of the camera, including its feed and configuration, but not a vendor signing key.

Model inference
Scale and recovery
ChainabilityCH 4
Cross-domain authority chain

The request crosses from the network into the camera operating system and then into the human security decisions driven by its feed.

Model inference
Reuse scaleSR 4
Shared fleet-wide primitive

The same vulnerable handler and exploit method apply across many affected Hikvision camera and recorder models.

Operational assumption
Execution scaleSX 4
Remote fleet-scale execution

Internet scanning and public tooling allow the request to be repeated across exposed devices without physical access.

Operational assumption
Recovery burdenOR 3
Coordinated operational recovery

Recovery requires patched firmware, verification that persistence was removed, and reset or credential rotation where compromise is suspected.

Operational assumption
Confidence and status
Evidence strengthEV 4
Field-confirmed evidence

NVD supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.

Source-backedNVD
LivenessLS Patch available
A patch is available

A vendor fix is available, while deployment and upgrade completion remain separate operational questions.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandEMERGENCY
  2. No adjustment

    The EMERGENCY base band remains final because no separate cap or systemic uplift applies. Root access exposes live and stored surveillance video and can change the visual evidence that guards or operators rely on.

  3. Final candidate bandEMERGENCY
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:PERCEPTION_TO_ACTION/RE:4/EC:4/EX:4/PH:3/DP:4/AT:3/CH:4/SR:4/SX:4/OR:3/EV:4/LS:PATCH_AVAILABLERead the scoring method →

Authority · Co-dominant path

Account authority

The attacker gains root-level service and configuration authority on the camera or recorder, but not the vendor firmware-signing root.

EMERGENCY
  1. accessSource-backed

    Network-reachable without prior access

    An exposed Hikvision web service accepts the command-injection request without authentication.

    EvidenceNVD

  2. boundaryModel inference

    Cross-domain authority chain

    A compromised camera can bridge from its exposed service into the local network, connected services, and stored surveillance data.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Administrative or command authority

    The attacker gains root-level service and configuration authority on the camera or recorder, but not the vendor firmware-signing root.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Account authority

    The attacker gains root-level service and configuration authority on the camera or recorder, but not the vendor firmware-signing root.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Coordinated operational recovery

    Possible implants make recovery more than a password change: devices need patched firmware, reflash or reset, and credential review.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 4
Network-reachable without prior access

An exposed Hikvision web service accepts the command-injection request without authentication.

Source-backedNVD
Execution complexityEC 4
Straightforward operation

One public HTTP request is sufficient to obtain operating-system command execution.

Source-backedNVD
ExposureEX 4
Reach and effort support the same exposure

The documented reach and required effort are equally permissive, so neither reduces the other.

Model inference
Consequence
Physical / safetyPH 2
Operational safety effect

Operating-system takeover can interrupt camera availability, while direct physical actuation is outside this authority-focused path.

Model inference
Data / perceptionDP 3
Sensitive device or personal data

Root access exposes device credentials, configuration, firmware state, and surveillance material stored or processed by the device.

Model inference
AuthorityAT 3
Administrative or command authority

The attacker gains root-level service and configuration authority on the camera or recorder, but not the vendor firmware-signing root.

Model inference
Scale and recovery
ChainabilityCH 4
Cross-domain authority chain

A compromised camera can bridge from its exposed service into the local network, connected services, and stored surveillance data.

Model inference
Reuse scaleSR 4
Shared fleet-wide primitive

The unauthenticated injection primitive is reusable across affected models without obtaining a secret from each device.

Operational assumption
Execution scaleSX 4
Remote fleet-scale execution

Public scanners and exploit code support remote repetition across large numbers of internet-exposed devices.

Operational assumption
Recovery burdenOR 3
Coordinated operational recovery

Possible implants make recovery more than a password change: devices need patched firmware, reflash or reset, and credential review.

Operational assumption
Confidence and status
Evidence strengthEV 4
Field-confirmed evidence

NVD supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.

Source-backedNVD
LivenessLS Patch available
A patch is available

A vendor fix is available, while deployment and upgrade completion remain separate operational questions.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandCRITICAL
  2. Systemic uplift

    The CRITICAL base band rises to EMERGENCY because unauthenticated root access is remotely reusable across a large camera population and recovery requires coordinated patching and incident review.

  3. Final candidate bandEMERGENCY
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:ACCOUNT_AUTHORITY/RE:4/EC:4/EX:4/PH:2/DP:3/AT:3/CH:4/SR:4/SX:4/OR:3/EV:4/LS:PATCH_AVAILABLERead the scoring method →

Systemic · Co-dominant path

Fleet control plane

The attacker aggregates root access on many cameras; this is not authority over Hikvision's legitimate fleet-management or signing infrastructure.

EMERGENCY
  1. accessSource-backed

    Network-reachable without prior access

    Every internet-exposed affected camera presents the same unauthenticated web entry point.

    EvidenceNVD

  2. boundaryModel inference

    Cross-domain authority chain

    The shared bug turns individual camera compromise into reusable botnet enrollment and command-and-control infrastructure.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Bounded function authority

    The attacker aggregates root access on many cameras; this is not authority over Hikvision's legitimate fleet-management or signing infrastructure.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Fleet control plane

    The attacker aggregates root access on many cameras; this is not authority over Hikvision's legitimate fleet-management or signing infrastructure.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Coordinated operational recovery

    Operators must patch, verify, and potentially reflash every exposed device because one compromised node can remain in the botnet.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 4
Network-reachable without prior access

Every internet-exposed affected camera presents the same unauthenticated web entry point.

Source-backedNVD
Execution complexityEC 4
Straightforward operation

Automated public tooling can issue the same command-injection request to each discovered device.

Source-backedNVD
ExposureEX 4
Reach and effort support the same exposure

The documented reach and required effort are equally permissive, so neither reduces the other.

Model inference
Consequence
Physical / safetyPH 2
Operational safety effect

Coordinated camera outages or falsified feeds can weaken security monitoring across many sites, without claiming direct actuator control.

Model inference
Data / perceptionDP 2
Operational data in scope

A botnet-scale compromise exposes device inventory, configuration, and operational telemetry across the affected population.

Model inference
AuthorityAT 2
Bounded function authority

The attacker aggregates root access on many cameras; this is not authority over Hikvision's legitimate fleet-management or signing infrastructure.

Model inference
Scale and recovery
ChainabilityCH 4
Cross-domain authority chain

The shared bug turns individual camera compromise into reusable botnet enrollment and command-and-control infrastructure.

Model inference
Reuse scaleSR 4
Shared fleet-wide primitive

One exploit implementation works across the affected product population without a per-device credential.

Operational assumption
Execution scaleSX 4
Remote fleet-scale execution

Discovery and exploitation can run remotely at internet scale with no visit to each camera.

Operational assumption
Recovery burdenOR 3
Coordinated operational recovery

Operators must patch, verify, and potentially reflash every exposed device because one compromised node can remain in the botnet.

Operational assumption
Confidence and status
Evidence strengthEV 4
Field-confirmed evidence

NVD supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.

Source-backedNVD
LivenessLS Patch available
A patch is available

A vendor fix is available, while deployment and upgrade completion remain separate operational questions.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandCRITICAL
  2. Systemic uplift

    The CRITICAL base band rises to EMERGENCY because the same remote root primitive can be aggregated across many cameras and coordinated recovery extends beyond one device.

  3. Final candidate bandEMERGENCY
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:FLEET_CONTROL_PLANE/RE:4/EC:4/EX:4/PH:2/DP:2/AT:2/CH:4/SR:4/SX:4/OR:3/EV:4/LS:PATCH_AVAILABLERead the scoring method →

Triage implication

Verify the perception transition before acting on the band.

Triage beyond the first device: verify whether the reusable condition, propagation mechanism, and recovery dependency actually exist across the deployment.

Evidence ledger

Public sources used by this record.

Every named source includes a public link. Path review remains separate from citation coverage.

Published baseline

Keep exploit severity and consequence reasoning distinct.

RelationshipPaths model is higher
Baseline confidencehigh
Scored2026-06-03
v3.1 · 9.8 CRITICALNVD / CNA via NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Original scorer notes

The source narrative behind the structured explanation.

Retained for provenance and historical review, not as the recommended way to understand the assessment.

Read the original scorer notes

Assessment

CFSE Consequence Paths assesses Hikvision IP camera / NVR unauthenticated command injection (CVE-2021-36260) at EMERGENCY — the worst of 3 risk paths (perception, authority). The dominant consequence is manipulated perception that drives action.

Vulnerability

Hikvision IP camera / NVR unauthenticated command injection (CVE-2021-36260). Reported attack vector: Network (remote, unauthenticated HTTP to device web server).

CFSE Consequence Paths analysis

The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.

PERCEPTION_TO_ACTIONEMERGENCY

CPATH:1.0-candidate/TT:PERCEPTION_TO_ACTION/RE:4/EC:4/EX:4/PH:3/DP:4/AT:3/CH:4/SR:4/SX:4/OR:3/EV:4/LS:PATCH_AVAILABLE

Exposure EX=4 (reachability and complexity-bound) · bands PH=CRITICAL · DP=EMERGENCY · AT=CRITICAL → base EMERGENCY · uplift active exploitation, fleet-reachable authority → assessed EMERGENCY.

Unauthenticated root RCE on the embedded web server (AV:N, AC:L, single crafted HTTP request, public PoCs) gives full control of the camera’s sensing function. Attacker can exfiltrate live/stored video (DP:4 live-camera/surveillance perception) AND suppress/falsify the camera’s perception output. Because the device is a physical-security sensor, blinding or fabricating its feed degrades the human/operator perception of safety-relevant reality, reducing physical-security margin for monitored premises (PH:3, perception_feeds_action=true). AT:3 reflects admin/service-level control over the device’s perception and config (not a signing/trust root). RE:4 internet-exposed; EC:4 trivial; CH:4 crosses network->device->physical-security boundary and reusable across fleet; SR:4 single primitive across millions of devices/dozens of models; SX:4 fleet-scale remote. OR:3 firmware update plus possible reflash since persistence is possible. EV:4 field-confirmed, in CISA KEV.

ACCOUNT_AUTHORITYEMERGENCY

CPATH:1.0-candidate/TT:ACCOUNT_AUTHORITY/RE:4/EC:4/EX:4/PH:3/DP:3/AT:3/CH:4/SR:4/SX:4/OR:3/EV:4/LS:PATCH_AVAILABLE

Exposure EX=4 (reachability and complexity-bound) · bands PH=CRITICAL · DP=CRITICAL · AT=CRITICAL → base CRITICAL · uplift active exploitation, fleet-reachable authority → assessed EMERGENCY.

Distinct device-takeover terminal: root code execution yields the highest authority on the embedded OS (full admin control of the device, config, credentials, firmware modification). AT:3 because this is admin/service/debug authority over a single device’s OS and config, not a cross-fleet signing root or OTA root-of-trust (no evidence the exploit yields the vendor signing key). DP:3 covers device credentials/firmware/op-state accessible post-root. PH:2 availability/workflow disruption of the device itself with no severe direct actuation harm. RE:4 internet-exposed unauth; EC:4 single request commodity toolkit; CH:4 enables lateral movement/pivot, crossing device->network->cloud/LAN boundaries (reusable bridge); SR:4 same primitive reusable fleet-wide; SX:4 mass remote exploitation observed. OR:3 reflash/factory-reset + credential rotation due to possible persistence/implants. EV:4 field-confirmed.

FLEET_CONTROL_PLANEEMERGENCY

CPATH:1.0-candidate/TT:FLEET_CONTROL_PLANE/RE:4/EC:4/EX:4/PH:3/DP:2/AT:2/CH:4/SR:4/SX:4/OR:3/EV:4/LS:PATCH_AVAILABLE

Exposure EX=4 (reachability and complexity-bound) · bands PH=CRITICAL · DP=HIGH · AT=CRITICAL → base CRITICAL · uplift active exploitation → assessed EMERGENCY.

Distinct scale/botnet terminal: a single reusable exploit primitive across an enormous installed base (millions of devices, dozens of models) enabled mass scanning and Mirai-style botnet enrollment. This is fleet-scale execution but NOT control of the vendor’s legitimate management/OTA control plane or signing root, so AT:2 (bounded aggregation of compromised nodes rather than authority over the trust root). RE:4 internet-exposed; EC:4 automated commodity toolkits; CH:4 cross-domain reusable bridge feeding botnet C2 infrastructure; SR:4 portable primitive/no per-device secret needed; SX:4 fleet-scale remote without per-device access. PH:2 / DP:2 reflect aggregate availability and telemetry impact rather than per-target safety/biometric data. OR:3 per-device firmware update/reflash across the fleet; recovery_needs_fleet_action left false since each owner patches their own device (no vendor signing-root rotation required). EV:4 field-confirmed, in KEV and exploit kits.

Published baseline

  • v3.1 9.8 CRITICAL — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H — NVD / CNA via NVD

The published baseline above is retained for source review. The registry records the reachable consequence path, including deployment-specific cyber-physical consequence, physical/safety impact, scale, and recovery burden.

Sources

Related paths

Compare the boundary, not only the product.

Cite this entryCFSE Consequence Paths Registry 1.0-candidate, CPATH-2026-0029 (“Hikvision IP camera / NVR unauthenticated command injection (CVE-2021-36260)”), paths.cfse.ai/CPATH-2026-0029 (published 2026-06-03).