CameraRisk

Hikvision DS-2CD4012F-(A)

cpe:2.3:*:hikvision:ds-2cd4012f-\(a\)

Vendor
Hikvision
Device type
Not derivable from CPE
Published vulnerabilities
2
In CISA KEV
1 KEV
Affected versions recorded
None specified
Data last built
5 September 2026

Security summary

2 published vulnerabilities affect this product according to NVD. 1 of them is in CISA's Known Exploited Vulnerabilities catalogue, which means confirmed exploitation in the wild.

Exploited: CVE-2017-7921.

Experimental risk indicator

Six components, listed separately. Two of the six have no public source for any product on this site. The components are not combined into a single score.

Known vulnerability count 2 bar scaled to 20
Highest published severity 9.8 CRITICAL
Confirmed exploitation yes 1 in CISA KEV
Exploitation probability EPSS >99.9% (highest)
Lifecycle status no source
Deployed exposure not measurable from public data

Published vulnerabilities

CVEPublishedCVSS SeverityEPSSFlags
CVE-2017-7923 2017-05-06 8.8 high 2.3% Vendor advisory
CVE-2017-7921 2017-05-06 9.8 critical >99.9% KEVVendor advisory

Affected versions

No version strings are recorded against this product in NVD. The CVE records name the product without constraining which firmware is affected.

Not recorded here

There is no public dataset of end-of-support dates, default credentials or shipped network services for this product, so those fields are absent rather than estimated. Whether any of these vulnerabilities is exploitable in a given deployment depends on firmware version, configuration and network position. None of those is recorded here.

This record is not unique. 57 other Hikvision products carry an identical published record: the same 2 vulnerabilities and the same recorded affected versions. This reflects how NVD files them. It does not mean the products are the same. This page holds nothing its siblings do not, so it is kept out of search results and the Hikvision page carries the family.

For the vendor's own advisories, see Hikvision.

Other Hikvision products

Vulnerability records from the National Vulnerability Database, matched to this product by CPE. Exploitation status from CISA KEV 2026.09.04. Exploitation probability from FIRST EPSS, 2026-09-04. Product name derived mechanically from the CPE identifier. See methodology.