CVE-2021-36260: Hikvision IP camera/NVR - Remote Command Execution

HoneyLabs honeypots recorded 844 probes matching CVE-2021-36260 from 7 distinct source IP addresses in the last 7 days. Severity is rated critical.

This CVE is on CISA's Known Exploited Vulnerabilities list.

Request paths that identify it

  • /SDK/webLanguage

Addresses probing it

Source IPProbesNetworkCountry
195.182.16.23783Amarutu Technology LtdGermany
89.42.231.20052Amarutu Technology LtdThe Netherlands
49.207.15.173Atria Convergence Technologies Ltd.,India
188.191.165.83Intelsc Ltd.Russia
84.54.70.181Uzbektelekom Joint Stock CompanyUzbekistan
134.249.29.1721Kyivstar PJSCUkraine
91.92.47.1161TechTies Inc.The Netherlands

Networks it comes from

ASNOrganisationProbesSource IPs
AS206264Amarutu Technology Ltd8352
AS50577Intelsc Ltd.31
AS55577Atria Convergence Technologies Ltd.,31
AS197170TechTies Inc.11
AS15895Kyivstar PJSC11
AS8193Uzbektelekom Joint Stock Company11

Captured requests

  • /SDK/webLanguage

HTTP client fingerprints (JA4H)

  • ge11nn09en_5f96af7f1814
  • po11nn0400_fdcc3615ee04
  • ge11nn0400_17292dadbc7b
  • pu11nn0600_f8bf768a441b

CVE report

CVE report

Open a specific CVE from the CVE tracker.