Scans for Hikvision Intelligent Security API, (Sun, Jul 19th)

Hikvision Cameras Exposed by Recon Scans Targeting Intelligent Security API

A growing number of Hikvision cameras are being targeted by malicious scans designed to exploit their Intelligent Security API (ISAPI). The ISAPI is a feature-rich interface that allows third-party developers to integrate with Hikvision devices, but its potential security vulnerabilities have left these cameras exposed.

The SANS Institute’s honeypot network has detected recon scans against the /ISAPI/System/status endpoint, which returns system information in XML or JSON format. This endpoint appears to be an obvious choice for attackers seeking to profile ISAPI-enabled devices. What’s concerning is that many of these scans are using Basic authentication, which can leave passwords vulnerable if transmitted in the clear.

The ISAPI is designed to provide access to various features, including AI and facial recognition functions, as well as control over camera settings and management. While it’s well-documented by Hikvision, its potential for abuse has been raised by the recent scanning activity. It’s worth noting that the encryption methods used (AES 128 or 256 in CBC mode) can be bypassed if Basic authentication is used, rendering them ineffective.

The scans are likely an attempt to identify vulnerable devices and potentially exploit their ISAPI interfaces. While the SANS Institute has not captured complete requests with authentication data, it’s only a matter of time before attackers succeed in brute-forcing passwords or exploiting other vulnerabilities. The fact that these cameras are being targeted is a stark reminder of the need for secure configuration and proper deployment.

The use of Basic authentication and potential encryption weaknesses make these devices particularly vulnerable to attack. As always, users should exercise extreme caution when deploying IoT devices like Hikvision cameras, ensuring they are not exposed to the internet or placed in sensitive areas. This latest development serves as a timely reminder to review security configurations and take necessary precautions to prevent potential exploits.

For those responsible for managing Hikvision devices, this is an opportunity to reassess their security setup and consider implementing additional measures to mitigate potential risks. It’s essential to prioritize secure configuration, use strong authentication methods, and regularly update devices with the latest security patches. By taking proactive steps, you can minimize your exposure to these types of threats and protect your network from potential harm.


Source: SANS ISC — 2026-07-19