December 19, 2025
Dear Valued Partner:
Today, Hikvision publicly disclosed two vulnerabilities (CVE-2025-66173, CVE-2025-66174) in some Hikvision DVR products. The company has issued updated firmware, available on our website, to address the vulnerabilities.
Hikvision has rated this vulnerability as 6.2 and 6.5 respectively, using the CVSS v3.1 calculator. The list of affected products and technical details of the vulnerability can be found in our security advisory. Please check the advisory to learn the technical details.
While Hikvision is not aware of these vulnerabilities being exploited in the field, we encourage you to ensure proper cyber hygiene and install the updated firmware. To mitigate the risk of these vulnerabilities being exploited, please also advise to set up strong and complex passwords for their devices.
With this letter, we want to reassure you of Hikvision’s strong commitment to cybersecurity by following the standard Coordinated Disclosure Process. The vulnerabilities were reported to the Hikvision Security Response Center (HSRC) by Aaron J Jose, and Hikvision has been actively working with the researcher to patch and verify the successful mitigation.
Hikvision is a CVE Partner and is committed to continuing to work with third-party security researchers to find, patch, disclose and release updates to products in a timely manner that best protects the users of Hikvision products. To report any security issues or vulnerabilities in Hikvision products and solutions, please contact the Hikvision Security Response Center at hsrc@hikvision.com. On our website, Hikvision discloses the vulnerabilities and informs about the remediation in a transparent and responsible manner.
Hikvision strictly complies with the laws and regulations in all countries and regions where we operate and our efforts to ensure the security of our products go beyond what is mandated.
Please do not hesitate to contact our team with any questions or concerns.
Kind Regards,