As cited
Copy frozen at (site build).
ot ics
Scans for Hikvision Intelligent Security API
Internet-wide scans targeting Hikvision cameras have shifted to probing the OPEN Intelligent Security API (ISAPI), a REST-based interface that provides broad control over camera settings and features. The scans specifically target the /ISAPI/System/status endpoint to detect ISAPI-capable devices and potentially support credential brute-forcing. While ISAPI supports both Basic and Digest authentication with optional AES encryption, the encryption key derivation from passwords and exposed initialization vector undermine security if Basic authentication is used over unencrypted connections.
Why it matters: Organizations deploying Hikvision cameras connected to networks face reconnaissance and potential unauthorized access if cameras are internet-exposed or use weak credentials; practitioners should ensure cameras remain behind firewalls, enforce strong authentication, and deploy HTTPS with proper certificate management.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
ot ics
Scans for Hikvision Intelligent Security API
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
ot ics
Scans for Hikvision Intelligent Security API
Internet-wide scans targeting Hikvision cameras are now probing the Intelligent Security application programming interface (API), a REST-based endpoint that can fully control camera settings and manage devices. The ISAPI endpoint /ISAPI/System/status allows reconnaissance and potential password brute-forcing, and the API's encryption provides minimal security when basic authentication is used over HTTP.
Why it matters: Organizations with Hikvision cameras exposed to the internet face active reconnaissance targeting the API endpoint, requiring immediate verification that cameras are not internet-accessible and operate over HTTPS with strong credentials to prevent unauthorized access and camera compromise.
- Source published
- First seen by Cybersecurity Tracker