Causal model
What has to happen for this consequence to hold?
3 candidate paths · explicit source, inference, and assumption boundaries.
Perception · Co-dominant path
Perception-to-action
Root access exposes live and stored surveillance video and can change the visual evidence that guards or operators rely on.
Network-reachable without prior access
The vulnerable camera web service was reachable over the network, including on internet-exposed installations, without a prior account.
EvidenceNVD
Cross-domain authority chain
The request crosses from the network into the camera operating system and then into the human security decisions driven by its feed.
EvidenceNo direct citation — inspect the declared inference or assumption.
Safety-driving perception or intimate data
Root access exposes live and stored surveillance video and can change the visual evidence that guards or operators rely on.
EvidenceNo direct citation — inspect the declared inference or assumption.
Perception-to-action
Root access exposes live and stored surveillance video and can change the visual evidence that guards or operators rely on.
EvidenceNo direct citation — inspect the declared inference or assumption.
Coordinated operational recovery
Recovery requires patched firmware, verification that persistence was removed, and reset or credential rotation where compromise is suspected.
EvidenceNo direct citation — inspect the declared inference or assumption.
Decision rationale
Why this band?
The compact score is separated into the facts and judgments that produced it.
Reach and effort
- Reachability
RE 4 - Network-reachable without prior access
The vulnerable camera web service was reachable over the network, including on internet-exposed installations, without a prior account.
- Execution complexity
EC 4 - Straightforward operation
A public exploit can inject a command through one unauthenticated HTTP request; no memory-corruption chain is required.
- Exposure
EX 4 - Reach and effort support the same exposure
The documented reach and required effort are equally permissive, so neither reduces the other.
Consequence
- Physical / safety
PH 3 - Credible safety consequence
Suppressing or fabricating a security-camera feed can hide activity from operators and reduce the physical-security margin of the monitored site.
- Data / perception
DP 4 - Safety-driving perception or intimate data
Root access exposes live and stored surveillance video and can change the visual evidence that guards or operators rely on.
- Authority
AT 3 - Administrative or command authority
Command injection reaches operating-system control of the camera, including its feed and configuration, but not a vendor signing key.
Scale and recovery
- Chainability
CH 4 - Cross-domain authority chain
The request crosses from the network into the camera operating system and then into the human security decisions driven by its feed.
- Reuse scale
SR 4 - Shared fleet-wide primitive
The same vulnerable handler and exploit method apply across many affected Hikvision camera and recorder models.
- Execution scale
SX 4 - Remote fleet-scale execution
Internet scanning and public tooling allow the request to be repeated across exposed devices without physical access.
- Recovery burden
OR 3 - Coordinated operational recovery
Recovery requires patched firmware, verification that persistence was removed, and reset or credential rotation where compromise is suspected.
Confidence and status
- Evidence strength
EV 4 - Field-confirmed evidence
NVD supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.
- Liveness
LS Patch available - A patch is available
A vendor fix is available, while deployment and upgrade completion remain separate operational questions.
Decision trail
How the final band follows
- Base bandEMERGENCY
- No adjustment
The EMERGENCY base band remains final because no separate cap or systemic uplift applies. Root access exposes live and stored surveillance video and can change the visual evidence that guards or operators rely on.
- Final candidate bandEMERGENCY
Technical vector
CPATH:1.0-candidate/TT:PERCEPTION_TO_ACTION/RE:4/EC:4/EX:4/PH:3/DP:4/AT:3/CH:4/SR:4/SX:4/OR:3/EV:4/LS:PATCH_AVAILABLERead the scoring method →Authority · Co-dominant path
Account authority
The attacker gains root-level service and configuration authority on the camera or recorder, but not the vendor firmware-signing root.
Network-reachable without prior access
An exposed Hikvision web service accepts the command-injection request without authentication.
EvidenceNVD
Cross-domain authority chain
A compromised camera can bridge from its exposed service into the local network, connected services, and stored surveillance data.
EvidenceNo direct citation — inspect the declared inference or assumption.
Administrative or command authority
The attacker gains root-level service and configuration authority on the camera or recorder, but not the vendor firmware-signing root.
EvidenceNo direct citation — inspect the declared inference or assumption.
Account authority
The attacker gains root-level service and configuration authority on the camera or recorder, but not the vendor firmware-signing root.
EvidenceNo direct citation — inspect the declared inference or assumption.
Coordinated operational recovery
Possible implants make recovery more than a password change: devices need patched firmware, reflash or reset, and credential review.
EvidenceNo direct citation — inspect the declared inference or assumption.
Decision rationale
Why this band?
The compact score is separated into the facts and judgments that produced it.
Reach and effort
- Reachability
RE 4 - Network-reachable without prior access
An exposed Hikvision web service accepts the command-injection request without authentication.
- Execution complexity
EC 4 - Straightforward operation
One public HTTP request is sufficient to obtain operating-system command execution.
- Exposure
EX 4 - Reach and effort support the same exposure
The documented reach and required effort are equally permissive, so neither reduces the other.
Consequence
- Physical / safety
PH 2 - Operational safety effect
Operating-system takeover can interrupt camera availability, while direct physical actuation is outside this authority-focused path.
- Data / perception
DP 3 - Sensitive device or personal data
Root access exposes device credentials, configuration, firmware state, and surveillance material stored or processed by the device.
- Authority
AT 3 - Administrative or command authority
The attacker gains root-level service and configuration authority on the camera or recorder, but not the vendor firmware-signing root.
Scale and recovery
- Chainability
CH 4 - Cross-domain authority chain
A compromised camera can bridge from its exposed service into the local network, connected services, and stored surveillance data.
- Reuse scale
SR 4 - Shared fleet-wide primitive
The unauthenticated injection primitive is reusable across affected models without obtaining a secret from each device.
- Execution scale
SX 4 - Remote fleet-scale execution
Public scanners and exploit code support remote repetition across large numbers of internet-exposed devices.
- Recovery burden
OR 3 - Coordinated operational recovery
Possible implants make recovery more than a password change: devices need patched firmware, reflash or reset, and credential review.
Confidence and status
- Evidence strength
EV 4 - Field-confirmed evidence
NVD supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.
- Liveness
LS Patch available - A patch is available
A vendor fix is available, while deployment and upgrade completion remain separate operational questions.
Decision trail
How the final band follows
- Base bandCRITICAL
- Systemic uplift
The CRITICAL base band rises to EMERGENCY because unauthenticated root access is remotely reusable across a large camera population and recovery requires coordinated patching and incident review.
- Final candidate bandEMERGENCY
Technical vector
CPATH:1.0-candidate/TT:ACCOUNT_AUTHORITY/RE:4/EC:4/EX:4/PH:2/DP:3/AT:3/CH:4/SR:4/SX:4/OR:3/EV:4/LS:PATCH_AVAILABLERead the scoring method →Systemic · Co-dominant path
Fleet control plane
The attacker aggregates root access on many cameras; this is not authority over Hikvision's legitimate fleet-management or signing infrastructure.
Network-reachable without prior access
Every internet-exposed affected camera presents the same unauthenticated web entry point.
EvidenceNVD
Cross-domain authority chain
The shared bug turns individual camera compromise into reusable botnet enrollment and command-and-control infrastructure.
EvidenceNo direct citation — inspect the declared inference or assumption.
Bounded function authority
The attacker aggregates root access on many cameras; this is not authority over Hikvision's legitimate fleet-management or signing infrastructure.
EvidenceNo direct citation — inspect the declared inference or assumption.
Fleet control plane
The attacker aggregates root access on many cameras; this is not authority over Hikvision's legitimate fleet-management or signing infrastructure.
EvidenceNo direct citation — inspect the declared inference or assumption.
Coordinated operational recovery
Operators must patch, verify, and potentially reflash every exposed device because one compromised node can remain in the botnet.
EvidenceNo direct citation — inspect the declared inference or assumption.
Decision rationale
Why this band?
The compact score is separated into the facts and judgments that produced it.
Reach and effort
- Reachability
RE 4 - Network-reachable without prior access
Every internet-exposed affected camera presents the same unauthenticated web entry point.
- Execution complexity
EC 4 - Straightforward operation
Automated public tooling can issue the same command-injection request to each discovered device.
- Exposure
EX 4 - Reach and effort support the same exposure
The documented reach and required effort are equally permissive, so neither reduces the other.
Consequence
- Physical / safety
PH 2 - Operational safety effect
Coordinated camera outages or falsified feeds can weaken security monitoring across many sites, without claiming direct actuator control.
- Data / perception
DP 2 - Operational data in scope
A botnet-scale compromise exposes device inventory, configuration, and operational telemetry across the affected population.
- Authority
AT 2 - Bounded function authority
The attacker aggregates root access on many cameras; this is not authority over Hikvision's legitimate fleet-management or signing infrastructure.
Scale and recovery
- Chainability
CH 4 - Cross-domain authority chain
The shared bug turns individual camera compromise into reusable botnet enrollment and command-and-control infrastructure.
- Reuse scale
SR 4 - Shared fleet-wide primitive
One exploit implementation works across the affected product population without a per-device credential.
- Execution scale
SX 4 - Remote fleet-scale execution
Discovery and exploitation can run remotely at internet scale with no visit to each camera.
- Recovery burden
OR 3 - Coordinated operational recovery
Operators must patch, verify, and potentially reflash every exposed device because one compromised node can remain in the botnet.
Confidence and status
- Evidence strength
EV 4 - Field-confirmed evidence
NVD supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.
- Liveness
LS Patch available - A patch is available
A vendor fix is available, while deployment and upgrade completion remain separate operational questions.
Decision trail
How the final band follows
- Base bandCRITICAL
- Systemic uplift
The CRITICAL base band rises to EMERGENCY because the same remote root primitive can be aggregated across many cameras and coordinated recovery extends beyond one device.
- Final candidate bandEMERGENCY
Technical vector
CPATH:1.0-candidate/TT:FLEET_CONTROL_PLANE/RE:4/EC:4/EX:4/PH:2/DP:2/AT:2/CH:4/SR:4/SX:4/OR:3/EV:4/LS:PATCH_AVAILABLERead the scoring method →Triage implication
Verify the perception transition before acting on the band.
Triage beyond the first device: verify whether the reusable condition, propagation mechanism, and recovery dependency actually exist across the deployment.
Evidence ledger
Public sources used by this record.
Every named source includes a public link. Path review remains separate from citation coverage.
- advisoryNVD
NVD
Published baseline
Keep exploit severity and consequence reasoning distinct.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVE recordsCVE-2021-36260
Original scorer notes
The source narrative behind the structured explanation.
Retained for provenance and historical review, not as the recommended way to understand the assessment.
Read the original scorer notes
Assessment
CFSE Consequence Paths assesses Hikvision IP camera / NVR unauthenticated command injection (CVE-2021-36260) at EMERGENCY — the worst of 3 risk paths (perception, authority). The dominant consequence is manipulated perception that drives action.
Vulnerability
Hikvision IP camera / NVR unauthenticated command injection (CVE-2021-36260). Reported attack vector: Network (remote, unauthenticated HTTP to device web server).
CFSE Consequence Paths analysis
The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.
PERCEPTION_TO_ACTION → EMERGENCY
CPATH:1.0-candidate/TT:PERCEPTION_TO_ACTION/RE:4/EC:4/EX:4/PH:3/DP:4/AT:3/CH:4/SR:4/SX:4/OR:3/EV:4/LS:PATCH_AVAILABLE
Exposure EX=4 (reachability and complexity-bound) · bands PH=CRITICAL · DP=EMERGENCY · AT=CRITICAL → base EMERGENCY · uplift active exploitation, fleet-reachable authority → assessed EMERGENCY.
Unauthenticated root RCE on the embedded web server (AV:N, AC:L, single crafted HTTP request, public PoCs) gives full control of the camera’s sensing function. Attacker can exfiltrate live/stored video (DP:4 live-camera/surveillance perception) AND suppress/falsify the camera’s perception output. Because the device is a physical-security sensor, blinding or fabricating its feed degrades the human/operator perception of safety-relevant reality, reducing physical-security margin for monitored premises (PH:3, perception_feeds_action=true). AT:3 reflects admin/service-level control over the device’s perception and config (not a signing/trust root). RE:4 internet-exposed; EC:4 trivial; CH:4 crosses network->device->physical-security boundary and reusable across fleet; SR:4 single primitive across millions of devices/dozens of models; SX:4 fleet-scale remote. OR:3 firmware update plus possible reflash since persistence is possible. EV:4 field-confirmed, in CISA KEV.
ACCOUNT_AUTHORITY → EMERGENCY
CPATH:1.0-candidate/TT:ACCOUNT_AUTHORITY/RE:4/EC:4/EX:4/PH:3/DP:3/AT:3/CH:4/SR:4/SX:4/OR:3/EV:4/LS:PATCH_AVAILABLE
Exposure EX=4 (reachability and complexity-bound) · bands PH=CRITICAL · DP=CRITICAL · AT=CRITICAL → base CRITICAL · uplift active exploitation, fleet-reachable authority → assessed EMERGENCY.
Distinct device-takeover terminal: root code execution yields the highest authority on the embedded OS (full admin control of the device, config, credentials, firmware modification). AT:3 because this is admin/service/debug authority over a single device’s OS and config, not a cross-fleet signing root or OTA root-of-trust (no evidence the exploit yields the vendor signing key). DP:3 covers device credentials/firmware/op-state accessible post-root. PH:2 availability/workflow disruption of the device itself with no severe direct actuation harm. RE:4 internet-exposed unauth; EC:4 single request commodity toolkit; CH:4 enables lateral movement/pivot, crossing device->network->cloud/LAN boundaries (reusable bridge); SR:4 same primitive reusable fleet-wide; SX:4 mass remote exploitation observed. OR:3 reflash/factory-reset + credential rotation due to possible persistence/implants. EV:4 field-confirmed.
FLEET_CONTROL_PLANE → EMERGENCY
CPATH:1.0-candidate/TT:FLEET_CONTROL_PLANE/RE:4/EC:4/EX:4/PH:3/DP:2/AT:2/CH:4/SR:4/SX:4/OR:3/EV:4/LS:PATCH_AVAILABLE
Exposure EX=4 (reachability and complexity-bound) · bands PH=CRITICAL · DP=HIGH · AT=CRITICAL → base CRITICAL · uplift active exploitation → assessed EMERGENCY.
Distinct scale/botnet terminal: a single reusable exploit primitive across an enormous installed base (millions of devices, dozens of models) enabled mass scanning and Mirai-style botnet enrollment. This is fleet-scale execution but NOT control of the vendor’s legitimate management/OTA control plane or signing root, so AT:2 (bounded aggregation of compromised nodes rather than authority over the trust root). RE:4 internet-exposed; EC:4 automated commodity toolkits; CH:4 cross-domain reusable bridge feeding botnet C2 infrastructure; SR:4 portable primitive/no per-device secret needed; SX:4 fleet-scale remote without per-device access. PH:2 / DP:2 reflect aggregate availability and telemetry impact rather than per-target safety/biometric data. OR:3 per-device firmware update/reflash across the fleet; recovery_needs_fleet_action left false since each owner patches their own device (no vendor signing-root rotation required). EV:4 field-confirmed, in KEV and exploit kits.
Published baseline
- v3.1 9.8 CRITICAL —
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H— NVD / CNA via NVD
The published baseline above is retained for source review. The registry records the reachable consequence path, including deployment-specific cyber-physical consequence, physical/safety impact, scale, and recovery burden.
Sources
CFSE Consequence Paths Registry 1.0-candidate, CPATH-2026-0029 (“Hikvision IP camera / NVR unauthenticated command injection (CVE-2021-36260)”), paths.cfse.ai/CPATH-2026-0029 (published 2026-06-03).