CVE-2024-29949: Hikvision Ds-7604ni-k1\/4p\b\
High severity, CVSS 7.2. EPSS: 1.3% chance of exploitation in the next 30 days.
There is a command injection vulnerability in some Hikvision NVRs. This could allow an authenticated user with administrative rights to execute arbitrary commands.
Affected products
- Hikvision Ds-7604ni-k1\/4p\b\: up to and including V4.30.096build221220
- Hikvision Ds-7604ni-k1 / 4pb
- Hikvision Ds-7604ni-m1/4p
- Hikvision Ds-7604ni-m1\/4p: from 5.00.000, before 5.01.070 (fixed in 5.01.070)
- Hikvision Ds-76xxni-Mx: from V5.00.000, before V5.02.006 (fixed in V5.02.006)
- Hikvision Ds-76xxnxi-Ix
- Hikvision Ds-76xxnxi-Lx: from 5.00.000, before 5.02.006 (fixed in 5.02.006)
- Hikvision Ds-77xxni-Mx: from 5.00.000, before 5.02.006 (fixed in 5.02.006)
- Hikvision Ds-77xxnxi-Ix
- Hikvision Ds-77xxnxi-Lx: from 5.00.000, before 5.02.006 (fixed in 5.02.006)
- Hikvision Ds-86xxnxi-Ix
- Hikvision Ds-86xxnxi-Lx: from 5.00.000, before 5.02.006 (fixed in 5.02.006)
- Hikvision Ds-96xxnxi-Ix
- Hikvision Ds-96xxnxi-Lx: from 5.00.000, before 5.02.006 (fixed in 5.02.006)
- Hikvision Ds-96xxxni-Mxx: from 5.00.000, before 5.02.006 (fixed in 5.02.006)
- Hikvision Ids-76xxnxi-Mx: from 5.00.000, before 5.02.006 (fixed in 5.02.006)
- Hikvision Ids-77xxnxi-Mx: from 5.00.000, before 5.02.006 (fixed in 5.02.006)
- Hikvision Ids-96xxxmxi-Mxx: from 5.00.000, before 5.02.006 (fixed in 5.02.006)
Published 2024-04-02. Last modified 2026-06-17.