There is a heap buffer overflow vulnerability in some Hikvision cameras, which may allow unauthenticated attackers to cause device malfunction by sending specially crafted packets.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-61390 represents a critical supply chain risk affecting Hikvision network cameras through a heap buffer overflow vulnerability (CWE-122) that requires no authentication to exploit. Attackers can trigger device malfunction by crafting and transmitting specially formatted packets to vulnerable cameras, potentially disrupting surveillance infrastructure across enterprise and critical infrastructure environments. The CVSS score of 7.7 reflects the high severity of unauthenticated remote exploitation capability, making this particularly dangerous for organizations with internet-exposed camera deployments or those within reach of network-adjacent attackers.
While this specific CVE lacks mapped MITRE ATT&CK techniques, Casky's 754 security skills powered by Claude AI with extended reasoning would help practitioners detect related attack patterns by analyzing network traffic anomalies, malformed packet structures, and device behavior deviations. Practitioners using Casky would identify reconnaissance activities (initial network scanning of camera management interfaces), exploitation attempts (abnormal packet sequences triggering buffer conditions), and impact assessment (sudden device unavailability or resource exhaustion). The platform's skills would correlate indicators such as unexpected connection patterns to camera ports, payload analysis revealing buffer-triggering packet structures, and device logs showing memory corruption events—enabling security teams to detect and respond to exploitation attempts before attackers achieve persistent access or lateral movement within critical surveillance networks.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-61390. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation