Certain Hikvision products contain a command injection vulnerability in the web server due to the insufficient input validation. An attacker can exploit the vulnerability to launch a command injection attack by sending some messages with malicious commands.
id: CVE-2021-36260
info:
name: Hikvision IP camera/NVR - Remote Command Execution
author: pdtea
...