CVE-2026-0709 is an authenticated command execution vulnerability in Hikvision Wireless Access Point (WAP) firmware (notably DS-3WAP521-SI, DS-3WAP522-SI, DS-3WAP621E-SI, DS-3WAP622E-SI, DS-3WAP623E-SI, DS-3WAP622G-SI) caused by insufficient input validation of attacker-controlled data in crafted packets sent to the device after authentication. An attacker with valid credentials can inject and execute arbitrary OS commands on the access point by sending specially crafted packets containing malicious commands, resulting in command execution with device privileges.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a minimal Python PoC/skeleton for testing an authenticated command-injection/RCE condition in Hikvision wireless APs claimed as CVE-2026-0709. Structure: - README.md: Explains intended workflow and explicitly notes the script is a template requiring the user to fill in the real vulnerable endpoint path, parameter name, and correct authentication logic. - hikvision_cve_2026_0709.py: Single-file CLI tool using `requests.Session()`. Exploit flow/capabilities: 1) Builds a base URL from user-supplied host/port and HTTP vs HTTPS. 2) Authenticates via a placeholder POST to `/login` with form fields `username` and `password` (no robust success check beyond HTTP 200). 3) Sends a second POST to a placeholder path `vulnerable/path` with form field `param` containing an injection string `127.0.0.1; <cmd>;` (default command `id`). 4) Prints HTTP status and response body for manual confirmation. Notable limitations: - The vulnerable endpoint and parameter are not implemented (placeholders), so the code is not directly usable without customization. - TLS verification is disabled (verify=False) and urllib3 warnings are suppressed. Overall purpose: a lab/testing template to validate authenticated RCE via command injection once the real CVE-specific request details are supplied.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Unknown (listed as a trending CVE affecting Hikvision Wireless Access Point; no technical details provided in the content).
Unknown (listed as a trending CVE affecting Hikvision Wireless Access Point; no technical details provided in the content).
Unknown (listed as a trending CVE affecting Hikvision Wireless Access Point; no technical details provided in the content).
An authenticated command execution vulnerability in Hikvision WAP firmware caused by insufficient input validation, allowing an authenticated attacker to send crafted packets and execute arbitrary commands on affected devices.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.