CVE-2020-7057: Hikvision Ds-7204hghi-f1 Firmware
Medium severity, CVSS 5.3. EPSS: 1.1% chance of exploitation in the next 30 days.
Hikvision DVR DS-7204HGHI-F1 V4.0.1 build 180903 Web Version sends a different response for failed ISAPI/Security/sessionLogin/capabilities login attempts depending on whether the user account exists, which might make it easier to enumerate users. However, only about 4 or 5 failed logins are allowed.
Affected products
- Hikvision Ds-7204hghi-f1 Firmware: version 4.0.1 only
Published 2020-01-14. Last modified 2026-06-17.