Hikvision fixes two access control vulnerabilities
Hikvision has released fixes for two security vulnerabilities affecting its access control software and several intercom products. The flaws carry CVSS scores of 7.1 and 5.2.
The company detailed the issues in two advisories published on September 10. One affects HikCentral Access Control. The other concerns a range of Hikvision intercom products.
HikCentral flaw allows unauthorized API access
The more severe vulnerability, tracked as CVE-2026-85545, affects HikCentral Access Control V2.5.0 and earlier versions.
Hikvision said authenticated users with low-level privileges could access API interfaces outside their assigned role.
The vulnerability has a CVSS v3.1 score of 7.1. Hikvision fixed the issue in version 2.5.1 and advises users to upgrade.
SECURITY UPDATE
CVE-2026-85545
HikCentral Access Control
CVSS score: 7.1
Fixed in: V2.5.1CVE-2026-85544
Selected Hikvision intercom products
CVSS score: 5.2
Risk: forged M1 cards
Intercom vulnerability affects M1 cards
The second vulnerability, CVE-2026-85544, affects several Hikvision intercom products.
According to Hikvision, an improper encryption configuration could allow attackers to forge M1 cards. The flaw has a CVSS v3.1 score of 5.2.
Hikvision has released firmware updates for the affected devices. The company also said products with the “M1 Card Encryption” feature enabled are not affected.
Independent researchers reported both vulnerabilities to the Hikvision Security Response Center.
















