Loading
Hikvision DVR DS-7204HGHI-F1 V4.0.1 build 180903 Web Version sends a different response for failed ISAPI/Security/sessionLogin/capabilities login attempts depending on whether the user account exists, which might make it easier to enumerate users. However, only about 4 or 5 failed logins are allowed.
Use CWE-307, Hikvision vendor hub and Ds-7204hghi-F1 Firmware product page to widen CVE-2020-7057 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-66174 and CVE-2025-66173 for nearby disclosures in the same product family.