# Spike in CVE-2021-36260 Exploitation Attempts Against Hikvision DVR/NVR Devices in Ukraine

> GreyNoise observed a nine-day surge (Sep 23 - Oct 1, 2026) of CVE-2021-36260 command-injection attempts against Hikvision IP camera/NVR devices in Ukraine, sent almost entirely by four IPs (three PureVPN-associated exit nodes on AS56630 in Lithuania, plus one Ukrainian domestic IP with low-confidence linkage) using the projectdiscovery nuclei template. Every recorded request from the four IPs was the same command test and nothing was installed. No actor is named.

- **Published:** 2026-10-08T00:00:00Z
- **Last reviewed:** 2026-10-08T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3050
- **ID:** TL-2026-3050
- **Severity:** HIGH (CVSS 9.8)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 11 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2021-36260

## Description

GreyNoise reports a surge of exploitation attempts against Hikvision IP camera and NVR products in Ukraine between 21 September and 1 October 2026 (UTC), tagged 'Hikvision IP Camera RCE CVE-2021-36260 Attempt'. Attempts against Ukraine had been rare since early July and there was almost nothing on 22 September. On 23 September attempts jumped from near zero, with four IPs sending almost all of them. Three of the IPs (195.238.124.178, 195.238.124.181, 195.238.124.188) are commercial VPN exit nodes on AS56630 in Lithuania associated with PureVPN, and GreyNoise assesses that activity as attributable to a single entity. The fourth is an unnamed Ukrainian domestic IP that on 21 September sent connection attempts to service ports in Ukraine with no exploit; GreyNoise rates its link to the other three as low confidence. The four IPs made no exploitation attempts against GreyNoise sensors outside Ukraine, and none were seen from any of them after 1 October (checked to 7 October). Every recorded request from the four IPs was the same command test, with nothing to install. GreyNoise matched the traffic to the public projectdiscovery nuclei template 'Hikvision IP camera/NVR - Remote Command Execution'.

CVE-2021-36260 is an unauthenticated OS command injection (CWE-78) in the web server of many Hikvision products, rated CVSS 3.1 9.8. It needs only network access to the device's HTTP(S) port, with no credentials or user interaction. The researcher WatchfulIP found it on 20 June 2021 and said it dates back to at least 2016. Hikvision and the researcher published advisories on 18 September 2021, and NVD published the CVE on 2021-09-22. CISA added it to the Known Exploited Vulnerabilities catalog on 2022-01-10. The public nuclei template exercises it with two requests: a PUT to /SDK/webLanguage carrying an XML body whose <language> element contains a $(echo <random-12-char-string>>webLib/x) command substitution, then a GET of /x to read the string back. A response containing the random string confirms command execution on the device. This is a harmless proof-of-execution check, and the same vulnerability has been used for botnet recruitment, notably by the Mirai-based Moobot in December 2021.

GreyNoise notes that the surge coincided with escalated Russian missile and drone strikes on Ukraine but states it cannot say whether the two are connected. The possible motive (battlespace awareness through compromised cameras) is unconfirmed speculation. GreyNoise also records a separate global rise in CVE-2021-36260 detections that did not come from these four IPs. The source gives no request counts, JA3/JA4 fingerprints, user agents, firmware versions, malware, hashes, domains or mitigations. Because PureVPN is a commercial service, the egress IPs may be shared with other users.

## MITRE ATT&CK

- T1595.001 Scanning IP Blocks
- T1595.002 Vulnerability Scanning
- T1588.002 Tool
- T1190 Exploit Public-Facing Application
- T1059.004 Unix Shell
- T1090 Proxy

## Sources

- [Spike in Attacks Targeting Digital Video Recorders in Ukraine (GreyNoise)](https://www.greynoise.io/blog/hikvision-camera-exploitation-attempts-ukraine)
- [GreyNoise Timeline: Ukraine Hikvision exploitation](https://www.greynoise.io/chronicle/gntl-20261006-ukraine-hikvision-exploitation)
- [NVD - CVE-2021-36260](https://nvd.nist.gov/vuln/detail/CVE-2021-36260)
- [projectdiscovery nuclei template CVE-2021-36260](https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-36260.yaml)
- [WatchfulIP: Hikvision IP Camera Unauthenticated RCE](https://watchfulip.github.io/2021/09/18/Hikvision-IP-Camera-Unauthenticated-RCE.html)
- [CISA Known Exploited Vulnerabilities catalog (CVE-2021-36260 added 2022-01-10)](https://www.cisa.gov/known-exploited-vulnerabilities-catalog)
- [SecurityWeek: Moobot botnet targets Hikvision devices via recent vulnerability](https://www.securityweek.com/moobot-botnet-targets-hikvision-devices-recent-vulnerability/)
- [ThreatDown: Thousands of Hikvision video cameras remain unpatched and vulnerable to takeover](https://www.threatdown.com/blog/thousands-of-hikvision-video-cameras-remain-unpatched-and-vulnerable-to-takeover/)
- [SentinelOne Vulnerability Database: CVE-2021-36260](https://www.sentinelone.com/vulnerability-database/cve-2021-36260/)
- [GreyNoise tag: Hikvision IP Camera RCE CVE-2021-36260 Attempt](https://viz.greynoise.io/tag/hikvision-ip-camera-rce-cve-2021-36260-attempt)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3050
