Search results

  1. U

    Unauthenticated Remote Code Execution (RCE) vulnerability in Hikvision IP camera/NVR firmware (CVE-2021-36260)

    Hmmmm. You mean the PC ethernet cable connected to NVR and assigned an ip in camera’s range? Probably be easier to change one camera to LAN IP on NVR segment and test it with PC. Would that work? All cameras are same model/firmware. Anyway, cameras are 2142FWD and I’m fairly certain they are...
  2. U

    Unauthenticated Remote Code Execution (RCE) vulnerability in Hikvision IP camera/NVR firmware (CVE-2021-36260)

    I don't think that is a dumb question. I can always use helpful suggestions. The way your question is worded, the answer is 'yes'. I'm on a 192.168.x.x network and my NVR has an IP on that same network segment. The NVR is configured to use a non-routable IP for the cameras. The NVR is...
  3. U

    Unauthenticated Remote Code Execution (RCE) vulnerability in Hikvision IP camera/NVR firmware (CVE-2021-36260)

    I use a non-routable IP. That said, substituting your commandline for my own situation, here is one result, which defaults to port 80. So, all is good. % Python3.9 ~/Desktop/hikvision.py --rhost 192.168.254.4 --check Hikvision CVE-2021-36260 PoC by bashis <mcw noemail eu> (2021) Checking...
  4. U

    Unauthenticated Remote Code Execution (RCE) vulnerability in Hikvision IP camera/NVR firmware (CVE-2021-36260)

    Thanks. Result is "cannot establish connection". :) As expected, all is good.
  5. U

    Unauthenticated Remote Code Execution (RCE) vulnerability in Hikvision IP camera/NVR firmware (CVE-2021-36260)

    This didn't work using an iMac. Later I'll fire up my linux machine and try again. Admittedly I'm not proficient in this sort of stuff and additionally may have incorrectly installed Python3 on my Mac. I named the file hikvision.py rather than the name presented at GitHub. Python3 hikvision.py...
  6. U

    Unauthenticated Remote Code Execution (RCE) vulnerability in Hikvision IP camera/NVR firmware (CVE-2021-36260)

    Thanks for the updated link. My hardware is not on that list :), it seems to apply to newer hardware than I have. I earlier posted a typo for my NVR. It's a DS-7716NI-SP (16 port), circa 2015, not a 716NI The posted link also points to a FAQ which offered me useful info, including the fact...
  7. U

    Unauthenticated Remote Code Execution (RCE) vulnerability in Hikvision IP camera/NVR firmware (CVE-2021-36260)

    Failed to mention in prior post that my NVR is on connected to internet except for NTP. The cameras also do not see the internet.
  8. U

    Unauthenticated Remote Code Execution (RCE) vulnerability in Hikvision IP camera/NVR firmware (CVE-2021-36260)

    Adding my thanks to the great work on finding this vulnerability. One thing that has always bugged me is that I can never figure out which firmware updates to apply (USA equipment) from 2016. My NVR is DS-716NI-SP (16 port). The effected lists here do not have a '-SP'. My cameras are...
  9. U

    Confused about correct firmware file

    As OP, I asked this question 4 yrs ago. In case anyone is curious, the most recent firmware update for my 2142's was v5.5.82_190220_0 dated Dec 2019. It took me a very long time to discover that the updates for the camera are in files referred to as "IPC R6 Platform". My 7716 NVR is updated to...
  10. U

    Hikvision-VCA Search is not working

    It is in the log. And I can view it from the log. But that is not the same as VCA search. The search sez "no pictures found". Now I'm thinking that there is no room on my hard drive to store a "picture". The HDD is set up to overwrite and my 2 4g hdd's have several months on them that they...
  11. U

    Hikvision-VCA Search is not working

    Sorry I wasn't clear. I'm want to search on NVR. At one time VCA searching worked. My objective is to glance at my cameras on the NVR monitor (it's set to record events) and immediately see if there is a 'critter' in the intrusion area (outlined by a warning box). A secondary objective...
  12. U

    Hikvision-VCA Search is not working

    I have a HikVision NVR 7716 (v3.4.5 firmware, the latest avail for my NVR) & dome cameras 2142fwd. I can set up intrusion & line crossing but I cannot perform a VCA search on my NVR (no file found). That is, it is not recording at NVR any events. I have the NVR set to record events over 24hr/7...
  13. U

    Backdoor found in Hikvision cameras

    That is pretty much the way I have set it up. I don't use DHCP. My NVR is assigned static IP on the LAN network. The gateway is my router/firewall appliance (I use Netgate's pfSense) My camera's are assigned static IP's 192.168.254.x iVMS4200 on an iMac can access the camera's My safari...
  14. U

    Backdoor found in Hikvision cameras

    Sorry, I don't grasp what you are saying. Indeed the example is a HVision NVR /w (16) PoE ports. And yes, there must be 2 interfaces at play for each camera. And yes, 192.168.254.0 network is dedicated to cameras. That said, my belief is (was?) that 192.168.254.0/24 is non-routable. Perhaps...
  15. U

    Backdoor found in Hikvision cameras

    I do the same. For example, 192.168.254.x is a non-routable IP. A typical camera setting in NVR is 192.168.254.101 and the NVR on a 192.168.x.x network has no problem seeing that camera. And I can point my browser to that IP and see the camera. The camera is blocked at my firewall and does not...
  16. U

    IR wavelength Spec?

    Thanks for wavelength explanation. I’m looking at over 100 ft. The Speco Technologies IR80 advertises up to 147. I plan to locate the light approx 80 ft from my camera and aim it to illuminate the far corner of my yard. The few products I’ve looked at have very short 12v power cords so I’ll...
  17. U

    HikVision Dome cameras with BAD night vision

    Try cleaning your dome lense. Carefully. My 2cd2142 lense reflects back dust particles. This is not noticeable in the day but at night it's quite annoying. Usually I can just wipe the outside with a clean rag. Sometimes I also need to use a lense cleaner. If it gets really bad I might need...
  18. U

    IR wavelength Spec?

    I'm thinking of buying accessory IR lighting for my Hikvision 2cd2142fwd cameras. They are mounted outdoors and I want to extend the range of night visibility. Lights I've looked at mention 850nm wavelength and not all cameras operate in this range. I cannot find any spec for my 2142 camera...
  19. U

    iOS updated and now access of Hikvision app broken

    False alarm. Rebooted my wifi & all is well.
  20. U

    iOS updated and now access of Hikvision app broken

    On my iphone i have been running iVMS 4500 app. Today I updated my phone to iOS 12.4 from whatever I was running before (v12.3.x). Now I get a "connection failure" trying to view the cameras. Worked fine yesterday. My MAC runs iVMS 4200 and no problem accessing. Same with VLC on MAC, I can...
  21. U

    [76 77 96 NI-I] New Firmware v4.1.65

    Ahhh, such a small detail. My eyes saw NI, not NI-I. Thanks for saving me.
  22. U

    [76 77 96 NI-I] New Firmware v4.1.65

    Just wondering...The Hikvision USA site still has v3.4.5-170518 for the DS-7716NI-SP/16. Is it safe to update to the UK version or is that asking for trouble?
  23. U

    VPN Primer for Noobs

    You don't have anything else on your network you can connect to in order to test going beyond the router? An are you saying that when your are connected to your VPN and open the HikVision app on your mobile device you cannot view the live stream from the cameras? If you cannot view that way then...
  24. U

    VPN Primer for Noobs

    I don't know if leaving out the gateway is limiting your VPN access. I've never considered doing that before. When you are accessing via VPN can you access any other devices inside your network? The VPN should let your remote device appear as if it is on your network. I am able to access...
  25. U

    Easiest Way to Secure Camera System

    If you are using dhcp and static ip in the same network you must take care that you create an 'exclusion' so that the dhcp server won't step on the static addresses. This is also known as a dhcp pool (for allowed dhcp addresses). If no other devices are obtaining an IP from your Asus then...
  26. U

    Easiest Way to Secure Camera System

    Granted, maybe this isn't the correct place for this topic. I took 'securing the system' as preventing access to the WAN. A few years ago you mentioned non-routable addressing for cameras and I gave it a try. It works well for me, so thank you for that suggestion. The gateway of...
  27. U

    Easiest Way to Secure Camera System

    My router is not using NAT. I admit to not understanding how it can work w/o NAT but it does. It does provide a translation in this configuration. It does not use ip_tables. The router is capable of being configured for NAT but it works differently when configured in that manner. I've never...
  28. U

    Help with Hikvision 7616 NVR screen capture

    I have a 7716. With NVR set to playback of camera, in lower left of screen I have a bunch of icons (widgets). One of them is an image of a camera, or capture. I haven't done this in awhile but believe I must first insert a usb stick into NVR. Then capture (I think one of those widgets is for...
  29. U

    Easiest Way to Secure Camera System

    I didn't use DHCP to assign IP's. I made my cameras non-routable to the internet by defining in the NVR camera setup an ip address in the 192.168.254.x address range w/ gateway of 192.168.254.1. That is one of the address ranges that are defined as non-routable. So the camera's don't go out...
  30. U

    VPN Primer for Noobs

    It may be useful to check out the Synology user forum. I don't use my Synology NAS for my cameras but it does have that capability.
Top