← Back to browse · API

CVE-2022-28171

Severity
HIGH
CVSS
7.5
EPSS
0.49858
Risk score
47.45
CISA KEV
No
PoC
No
Published
2022-06-27
Modified
2024-09-16
First seen
2026-08-07
Aliases
EUVD-2022-32625, GHSA-PJ6V-V769-6JFP
Products
Hikvision:DS-A71024/48/72R,DS-A80624S,DS-A81016S,DS-A72024/72R,DS-A80316S,DS-A82024D V2.X ≤V2.3.8-6, Hikvision:DS-A71024/48R-CVS,DS-A72024/48R-CVS V1.X ≤V1.1.4
Sources
euvd EUVD-2022-32625

Description

The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to the insufficient input validation, attacker can exploit the vulnerability to execute restricted commands by sending messages with malicious commands to the affected device.

References