CVE-2026-16843 Details
Description
Some Hikvision Networking Products are vulnerable to authenticated command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution.
A vulnerability allowing authenticated command execution has been identified in certain Hikvision Wireless Access Point models. This issue arises from inadequate input validation, enabling attackers with valid credentials to send crafted packets containing malicious commands to the affected devices. As a result, arbitrary commands can be executed on the devices.
Users can download the fixed version from the Hikvision official website. The patched version for the DS-3WAP521-SI, DS-3WAP522-SI, DS-3WAP621E-SI, DS-3WAP622E-SI, DS-3WAP623E-SI, DS-3WAP622G-SI models is V1.1.6602 build260526. For the DS-3WG105G-SI, DS-3WG105GP-SI, DS-3WG210GP-SI, and DS-3WG507G-SI models, the fixed version is V1.0.6602 build260703.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 31, 2026CISA-ADP
Assessed Jul 31, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.hikvision.com/en/support/cybersecurity/security-advisory/command-execution-vulnerability-in-some-wireless-ap-products/ | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Hikvision DS-3WAP521-SI | <= V1.1.6601 build251223 |
CPE
Remediation
| |
| Hikvision DS-3WAP522-SI | <= V1.1.6601 build251223 |
CPE
Remediation
| |
| Hikvision DS-3WAP621E-SI | <= V1.1.6601 build251223 |
CPE
Remediation
| |
| Hikvision DS-3WAP622E-SI | <= V1.1.6601 build251223 |
CPE
Remediation
| |
| Hikvision DS-3WAP623E-SI | <= V1.1.6601 build251223 |
CPE
Remediation
| |
| Hikvision DS-3WAP622G-SI | <= V1.1.6601 build251223 |
CPE
Remediation
| |
| Hikvision DS-3WG105G-SI | <= V1.0.6601 build251223 |
CPE
Remediation
| |
| Hikvision DS-3WG105GP-SI | <= V1.0.6601 build251223 |
CPE
Remediation
| |
| Hikvision DS-3WG210GP-SI | <= V1.0.6601 build251223 |
CPE
Remediation
| |
| Hikvision DS-3WG507G-SI | <= V1.0.6601 build251223 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 3, 2026 | CVE Modified | [email protected] |
| Jul 31, 2026 | CVE Modified | CISA-ADP |
| Jul 31, 2026 | New CVE Received | [email protected] |
Volerion