Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > Nine-Day Scanning Surge Targets Unpatched Hikvision Cameras Across Ukraine
Nine-Day Scanning Surge Targets Unpatched Hikvision Cameras Across Ukraine
Read Time:3 Minute, 38 Second

Security researchers have tracked a sharp, nine-day spike in scanning and exploitation attempts against internet-exposed Hikvision surveillance equipment in Ukraine, with almost all of the activity aimed at a four-year-old command injection flaw that still haunts unpatched devices. The surge ran from September 21 through October 1, 2026, a period that overlapped with intensified Russian missile and drone strikes — though analysts have stopped short of linking the two.

A Sudden Spike After Months of Quiet

According to a timeline published by threat-intelligence firm GreyNoise, the activity began with low-key reconnaissance from a Ukrainian IP address on September 21, probing service ports without firing off an actual exploit. Two days later, on September 23, the picture changed: exploitation attempts shot up and continued at an elevated pace for more than a week, a level of focused attention on Ukrainian targets that hadn’t been seen in months.

Just four IP addresses were responsible for nearly all of the exploitation traffic. Three traced back to PureVPN exit nodes registered to AS56630 in Lithuania, while the fourth belonged to a domestic Ukrainian network that GreyNoise did not publicly identify. The firm assessed with low confidence that the Ukrainian address might be connected to the same operator running the VPN nodes, while cautioning that commercial VPN exits are shared infrastructure and can’t be treated as solid proof of a single actor acting alone.

An Old, Well-Known Flaw

The target of nearly every attempt was CVE-2021-36260, a critical command injection vulnerability in the web server component of various Hikvision cameras and network video recorders. The bug carries a maximum-severity CVSS score of 9.8 because it can be triggered remotely, without authentication or any user interaction, letting an attacker run arbitrary commands on the device’s underlying operating system.

Notably, the attackers appear to have relied on a publicly available Nuclei scanning template built specifically to probe for this flaw. Every logged request used the same basic command test with no follow-up payload, which points toward automated vulnerability sweeping rather than a hands-on-keyboard intrusion. GreyNoise was careful to frame its findings as evidence of exploitation attempts, not confirmed device takeovers — a distinction that matters a great deal when judging how serious this specific wave actually was.

Why Exposed Cameras Are a Real Risk

Even if this particular campaign turns out to be routine scanning rather than a targeted operation, the stakes around vulnerable surveillance hardware in a conflict zone are not hypothetical. Cybersecurity News has previously documented more than 80,000 exposed, vulnerable Hikvision devices discovered in a 2022 sweep, underscoring just how long this exposure problem has lingered. More pointedly, Ukrainian authorities disclosed in January 2024 that they had disabled two cameras that Russian intelligence services had compromised specifically to monitor Kyiv’s air defenses and critical infrastructure.

That history illustrates what’s plausible when a camera network goes unpatched and internet-facing — unauthorized remote command execution could, in principle, let an attacker watch live feeds, pivot into connected networks, or disable equipment at a sensitive moment. It does not, however, establish who is behind the current scanning wave or what their end goal might be.

What Operators Should Do

CISA and Hikvision have both published guidance for defending against CVE-2021-36260, and the fix is straightforward even though the exposure has proven durable. Organizations running Hikvision cameras or recorders — especially in Ukraine or other high-risk regions — should treat this as a prompt to check their exposure immediately. Recommended steps include:

  • Identify every Hikvision camera and NVR model in the environment and confirm which firmware version is installed.
  • Apply Hikvision’s official firmware patches for CVE-2021-36260 without delay.
  • Remove direct public internet access to camera management interfaces wherever possible.
  • Segment surveillance equipment onto its own network, isolated from core business or operational systems.
  • Monitor logs for repeated connection attempts to camera web services, particularly from VPN exit ranges.

It’s worth stressing that changing device passwords will do nothing here — this is an unauthenticated flaw in how the device parses incoming requests, so a firmware update is the only real remedy. Given how often this four-year-old bug keeps resurfacing in fresh campaigns, organizations that haven’t verified their patch status recently would be wise to do so now, regardless of whether they believe themselves to be a likely target.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on Nine-Day Scanning Surge Targets Unpatched Hikvision Cameras Across Ukraine, use the discussion on Forum.

>> forum community

Comments

Leave a Reply