Hikvision patches high-severity flaw in networking products
Hikvision has released firmware updates addressing a high-severity command execution vulnerability affecting several of its networking products.
The vulnerability, tracked as CVE-2026-16843, is caused by insufficient input validation. According to the company, an attacker with valid credentials and high-level privileges could send specially crafted packets containing malicious commands to an affected device.
Successful exploitation could allow arbitrary command execution and compromise the confidentiality, integrity and availability of the device. The vulnerability has received a CVSS v3.1 score of 7.2 out of 10.
Affected products include selected Hikvision wireless access points and network gateway models from the DS-3WAP and DS-3WG series. Hikvision has published corrected firmware versions for all listed devices.
Users and system administrators are advised to check their product model and installed firmware version and apply the relevant update available through Hikvision’s official website.

















