South Africans rely heavily on CCTV for safety, whether in businesses, municipal spaces, shopping centres, or private homes. Yet a series of recent cybersecurity alerts has placed one of the world’s largest suppliers — Hikvision — under renewed scrutiny.
In late September 2025, both international cybersecurity outlets and the SANS Internet Storm Center (ISC) flagged active attempts to exploit known flaws in Hikvision cameras. The news has reignited concerns about how vulnerable local surveillance systems are to hackers — and what that could mean for safety, privacy, and national security.

From 2017 to 2025: Old Vulnerabilities Resurface
The most prominent flaw is CVE-2017-7921, a vulnerability disclosed eight years ago. It affects certain Hikvision IP cameras and allowed attackers to bypass authentication, escalate privileges, and even change passwords.
Although Hikvision released firmware patches years ago, thousands of devices worldwide remain unpatched — particularly older or “grey-market” imports. According to ISC logs, malicious requests exploiting this flaw have spiked again in September 2025, using the base64-encoded “admin:11” credential trick to probe exposed devices.
This proves that while the vulnerability is not new, attackers still view it as fertile ground, especially in countries where outdated or unmaintained devices are common.
A New Critical Threat: CVE-2025-34067
Beyond the old issue, a fresh critical vulnerability (CVE-2025-34067) was disclosed this year. Rated with a CVSS score of 10.0, the flaw involves unsafe JSON deserialisation in Hikvision’s HikCentral software. It could allow unauthenticated remote command execution, giving hackers full control over systems.
Some media reports suggested global HikCentral deployments were exposed, but Hikvision has since clarified that this specific vulnerability affects domestic iSecure Center deployments in China — not its international versions. Even so, the disclosure highlights the risks of software supply chain dependencies and the global exposure of widely used surveillance platforms.
Why This Matters in South Africa
South Africa is one of Hikvision’s biggest markets in Africa. The cameras are used in:
- Municipal smart surveillance systems
- Shopping centres, office parks, and warehouses
- Residential estates and private homes
- Transport and logistics hubs
If these systems run outdated firmware, they could be remotely hijacked by attackers. Beyond privacy risks, this opens the door to:
- Disabling security feeds ahead of robberies or infrastructure attacks
- Extracting sensitive video data from businesses and municipalities
- Creating backdoors into larger IT networks
With South Africa already facing rising organised crime and infrastructure sabotage, weakly secured surveillance systems represent a serious national security blind spot.
What Can Be Done
Experts recommend:
- Check Firmware Versions — Ensure Hikvision devices are updated to the latest firmware from official sources.
- Patch Immediately — Older models vulnerable to CVE-2017-7921 should be updated or replaced.
- Restrict Internet Exposure — Cameras should not be directly accessible over the internet. Use VPNs or firewalls.
- Audit Access Control — Default credentials must be changed; strong passwords should be enforced.
- Vendor Verification — Avoid “grey imports” or unauthorised resellers that ship outdated stock without security support. In other words, always use an accredited dealer!

Why This Story Matters
South Africa’s growing reliance on technology to combat crime means cybersecurity is now a frontline safety issue. Hikvision vulnerabilities are not abstract technical flaws — they represent real-world risks in malls, municipalities, and homes across the country.
As hackers globally renew their focus on these systems, local businesses and government departments must act. Surveillance without cybersecurity is a false sense of security — and in a country facing rising violent crime, it is a risk South Africa cannot afford to ignore.
Nevertheless, what are your thoughts on this? Let us know below.
Be sure to read, Turn Your Old Smartphone into a CCTV Camera: Affordable Security at Your Fingertips, if you missed it.
FAQs for Hikvision hacking vulnerabilities
The main flaw, CVE-2017-7921, allows attackers to bypass authentication and take control of Hikvision cameras. It affects older, unpatched devices.
Yes. South Africa uses Hikvision cameras extensively. Unpatched systems in municipalities, malls, and homes are exposed to cyberattacks.
It’s a critical flaw in HikCentral software involving unsafe JSON handling. Hikvision says it affects domestic Chinese deployments, not global ones.
Users should update firmware, avoid exposing devices to the internet, change default passwords, and ensure purchases come from authorised vendors.
Compromised CCTV systems could aid criminals by disabling feeds or leaking data, undermining safety in a country already grappling with high crime.











