CVE-2015-4408: Hikvision Ds-76xxx Series Firmware

Medium severity, CVSS 6.5. EPSS: 1.3% chance of exploitation in the next 30 days.

Buffer overflow on Hikvision NVR DS-76xxNI-E1/2 and DS-77xxxNI-E4 devices before 3.4.0 allows remote authenticated users to cause a denial of service (service interruption) via a crafted HTTP request, aka the ISAPI issue.

Affected products

  • Hikvision Ds-76xxx Series Firmware: up to and including 3.3.4
  • Hikvision Ds-77xxx Series Firmware: up to and including 3.3.4

Published 2017-03-13. Last modified 2026-06-17.