THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-16843 (HIGH 7.2) — Some Hikvision Networking Products are vulnerable to authenticated command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary com

[NVD] CVE-2026-16843 (HIGH 7.2) — Some Hikvision Networking Products are vulnerable to authenticated command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary com

mednvdPublished 2026-07-31

CVE-2026-16843 CVSS: 7.2 HIGH Published: 2026-07-31T11:17:05.567

Some Hikvision Networking Products are vulnerable to authenticated command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution.

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-16843