A high-severity authenticated command execution flaw in Hikvision DS-3WAP series wireless access points, tracked as CVE-2026-0709 (CVSS 7.2), was disclosed as stemming from insufficient input validation in device firmware. An attacker with valid credentials can send specially crafted packets containing malicious commands to trigger arbitrary command execution, enabling device takeover scenarios that can support traffic interception, lateral movement, or disruption of wireless services—particularly if credentials are stolen, default, or obtained via an initial foothold.
Hikvision released patched firmware V1.1.6601 build 251223 to address the issue across affected models running V1.1.6303 build250812 and earlier, including DS-3WAP521-SI, DS-3WAP522-SI, DS-3WAP621E-SI, DS-3WAP622E-SI, DS-3WAP623E-SI, and (per reporting) DS-3WAP622G-SI. Organizations using these access points should prioritize upgrading firmware and reviewing access controls around device administration, as the exploitability hinges on possession of valid credentials and may be used as a second-stage escalation after an initial account compromise.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Security reports publicly disclosed technical details of CVE-2026-0709, including its CVSS 7.2 rating, affected Hikvision wireless access point models, and the risk of traffic interception, lateral movement, or wireless service disruption after credential compromise. Multiple outlets also highlighted Hikvision's remediation guidance and recommended defensive measures such as stronger access controls and network segmentation.
Hikvision released firmware version V1.1.6601 build251223 to fix CVE-2026-0709 in affected DS-3WAP models running V1.1.6303 build250812 and earlier. The update addresses a high-severity issue that could let an authenticated attacker hijack the device and gain control of its underlying operating system.
An independent researcher known as exzettabyte reported an authenticated command execution vulnerability in Hikvision DS-3WAP wireless access points, later assigned CVE-2026-0709. The flaw stems from insufficient input validation and can allow arbitrary command execution via crafted packets.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.