Between September 21 and October 1, 2026, Ukraine experienced an increase in attempts to exploit remote code execution vulnerabilities in video surveillance systems. This surge in activity primarily targeted an old vulnerability, CVE-2021-36260, present in certain Hikvision products, which remains unpatched in some instances.
Surge in Exploitation Attempts
The vulnerability, identified as a critical command injection flaw, allows attackers to control video surveillance devices without authentication. The increase in exploitation attempts coincided with Russian missile and drone strikes in Ukraine, though researchers have found no direct link between the cyber activities and the military actions.
GreyNoise, a cybersecurity firm, noted that while they observed numerous attempts to exploit the vulnerability, they did not confirm any successful breaches of surveillance systems. This distinction is crucial in understanding the potential impact and intent of the cyber activities.
Details on Cyber Activities
Initial reconnaissance efforts were recorded on September 21, when an IP address in Ukraine attempted to connect to service ports without executing an exploit. The rate of exploitation attempts increased significantly on September 23, continuing until October 1, marking a notable nine-day period of heightened activity.
Four IP addresses were primarily responsible for these attempts, with three associated with PureVPN exit nodes and one belonging to a Ukrainian network. GreyNoise attributed the VPN activity to a single entity, though they expressed low confidence in linking the Ukrainian IP address to this activity.
Impact and Mitigation Measures
The vulnerability exploited is serious, with a critical CVSS score of 9.8, due to its ability to facilitate unauthorized network access without user interaction. The activity employed a publicly available Nuclei template for testing purposes, suggesting automation rather than deliberate malware installation.
Historically, Hikvision cameras have been exposed to similar threats, with over 80,000 vulnerable devices reported in 2022. To mitigate risks, administrators should update firmware as per CISA’s recommendations, limit public access, and isolate surveillance systems from critical networks. Changing passwords is insufficient to address the underlying flaw.
The potential for compromised cameras to expose sensitive information is significant. Past incidents, such as the disabling of compromised cameras by Ukrainian authorities in 2024, highlight the risks involved. It remains essential for organizations to promptly address these vulnerabilities to protect sensitive locations and operations from espionage.
Enhance security operations by integrating threat intelligence lookup tools to reduce investigation time and improve response efficiency.
