SN No. HSRC-202605-03
Edit: Hikvision Security Response Center (HSRC)
Initial Release Date: 2026-05-08
Summary
Data transmission risks exist in older API versions used by cloud function modules of some Hikvision products, potentially allowing attackers to intercept data through network monitoring. Users are strongly advised to update their apps to the latest version and enable video encryption features.
CVE ID
CVE-2026-32683
Scoring
CVSS v3.1 is adopted in scoring these vulnerabilities (http://www.first.org/cvss/specification-document)
CVE-2026-32683
Base score: 5.3 (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
Affected Versions and Fix
Product Name
|
CVE ID
|
Affected Versions
|
HIK-Connect APP
|
CVE-2026-32683
|
Versions below V6.11.80
|
Users need to upgrade the APP version and enable the video encryption function.
Obtaining Fixed Version
Users can download the latest version from major app stores or perform version upgrades through the update module within the app.
Source of vulnerability information
The vulnerability was reported to EZVIZ Security Team by Cisco Talos.
Contact Us
To report any security issues or vulnerabilities in Hikvision products and solutions, please contact Hikvision Security Response Center at hsrc@hikvision.com.
Hikvision would like to thank all security researchers for your attention to our products.
Declaration
This document is provided on an “AS IS” basis and without warranties of any kind, either express or implied, including but not limited to the warranties of merchantability or fitness for a particular purpose.
Hikvision or any of its directly or indirectly controlled subsidiaries or its suppliers shall not be liable for any damages arising out of or in connection with the use of this document, including direct, indirect, incidental, special, or consequential damages.
Hikvision reserves the right to revise or update this document at any time.