CVE-2026-85544
Summary
| CVE | CVE-2026-85544 |
|---|---|
| State | PUBLISHED |
| Assigner | hikvision |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-10 13:20:32 UTC |
| Updated | 2026-09-18 10:17:06 UTC |
| Description | Some Hikvision intercom products utilize an immutable factory value which should be obtained from local network or physical interaction with the device within their main card, which may allow attackers to forge a legitimate main card, thereby gaining the permission to issue cards. |
Risk And Classification
Primary CVSS: v3.1 6.1 MEDIUM from [email protected]
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS: 0.001480000 probability, percentile 0.043630000 (date 2026-09-20)
Problem Types: CWE-798 | CWE-1310 | CWE-798 CWE-798 Use of Hard-coded Credentials | CWE-1310 CWE-1310 Missing Ability to Patch ROM Code
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 6.1 | MEDIUM | CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
| 3.1 | CNA | CVSS | 6.1 | MEDIUM | CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
CVSS v3.1 Breakdown
Attack Vector
PhysicalAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
NoneCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Hikvision | DS-KV9503 | affected V2.3.13 and the versions prior to it | Not specified |
| CNA | Hikvision | DS-KV6113 | affected V3.7.0 and the versions prior to it | Not specified |
| CNA | Hikvision | DS-KV6103 | affected V3.7.0 and the versions prior to it | Not specified |
| CNA | Hikvision | DS-KV6133 | affected V3.7.0 and the versions prior to it | Not specified |
| CNA | Hikvision | DS-KV8113 | affected V3.7.0 and the versions prior to it | Not specified |
| CNA | Hikvision | DS-KV8213 | affected V3.7.0 and the versions prior to it | Not specified |
| CNA | Hikvision | DS-KV8413 | affected V3.7.0 and the versions prior to it | Not specified |
| CNA | Hikvision | DS-KD8003 | affected V3.7.1 and the versions prior to it | Not specified |
| CNA | Hikvision | DS-KD8005 | affected V3.10.0 and the versions prior to it | Not specified |
| CNA | Hikvision | DS-KV6114 | affected V3.9.0 and the versions prior to it | Not specified |
| CNA | Hikvision | DS-KV6124 | affected V3.9.0 and the versions prior to it | Not specified |
| CNA | Hikvision | DS-KV6134 | affected V3.9.0 and the versions prior to it | Not specified |
| CNA | Hikvision | DS-KV8114 | affected V3.11.0 and the versions prior to it | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.hikvision.com/en/support/cybersecurity/security-advisory/security-vulnerabi... | [email protected] | www.hikvision.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Filipe Moreira (en)
There are currently no legacy QID mappings associated with this CVE.