Rapid7 Labs discovered three vulnerabilities in Hikvision DVRs that an attacker could remotely exploit to take complete control of the device. The vulnerabilities leave the devices open to denial of service attacks, remote code execution, and could allow attackers to remotely delete surveillance footage. Hikvision failed for months to respond to the disclosure, Rapid7 published a Metasploit exploit module. The vendor was first contacted about the flaws on September 15, according to CERT Coordination Center and then assigned CVE identifiers.”]