ZeroHour

Vulnerabilities

52 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-39950
A vulnerability has been found in Dahua products.

A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities to initiate device initialization.

NVD description · AI analysis pending
9.8
group max
<1%
  • dahuasecurity nvr4104-4ks2\/l firmware
  • dahuasecurity nvr4108-4ks2\/l firmware
  • dahuasecurity nvr4116-4ks2\/l firmware
  • +1 more
CVE-2023-3836
A vulnerability classified as critical was found in Dahua Smart Park Management up to 20230713.

A vulnerability classified as critical was found in Dahua Smart Park Management up to 20230713. This vulnerability affects unknown code of the file /emap/devicePoint_addImgIco?hasSubsystem=true. The manipulation of the argument upload leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-235162 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
9.874% PoC
  • dahuasecurity smart parking management
CVE-2023-3121
A vulnerability has been found in Dahua Smart Parking Management up to 20230528 and classified as problematic.

A vulnerability has been found in Dahua Smart Parking Management up to 20230528 and classified as problematic. This vulnerability affects unknown code of the file /ipms/imageConvert/image. The manipulation of the argument fileUrl leads to server-side request forgery. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-230800. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
4.6<1% PoC
  • dahuasecurity smart parking management
CVE-2022-30564
Some Dahua embedded products have a vulnerability of unauthorized modification of the device timestamp.

Some Dahua embedded products have a vulnerability of unauthorized modification of the device timestamp. By sending a specially crafted packet to the vulnerable interface, an attacker can modify the device system time.

NVD description · AI analysis pending
5.3<1%
  • dahuasecurity ipc-hf71242f-z-x firmware
  • dahuasecurity ipc-hf7442f-z-x firmware
  • dahuasecurity ipc-hf7842f-z-x firmware
  • +1 more
CVE-2022-45431
+3 in the same advisory: …45434 …45432 …45433
Some Dahua software products have a vulnerability of unauthenticated restart of remote DSS Server.

Some Dahua software products have a vulnerability of unauthenticated restart of remote DSS Server. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could unauthenticated restart of remote DSS Server.

NVD description · AI analysis pending
7.5
group max
<1%
  • dahuasecurity dhi-dss7016d-s2 firmware
  • dahuasecurity dhi-dss7016dr-s2 firmware
  • dahuasecurity dhi-dss4004-s2 firmware
  • +1 more
CVE-2022-45423
Some Dahua software products have a vulnerability of unauthenticated request of MQTT credentials.

Some Dahua software products have a vulnerability of unauthenticated request of MQTT credentials. An attacker can obtain encrypted MQTT credentials by sending a specific crafted packet to the vulnerable interface (the credentials cannot be directly exploited).

NVD description · AI analysis pending
7.5
group max
<1%
  • dahuasecurity dss express
  • dahuasecurity dss professional
  • dahuasecurity dhi-dss7016d-s2 firmware
  • +1 more
CVE-2022-30563
+3 in the same advisory: …30560 …30561 …30562
When an attacker uses a man-in-the-middle attack to sniff the request packets with success logging in through ONVIF, he can log in to the device by replaying th

When an attacker uses a man-in-the-middle attack to sniff the request packets with success logging in through ONVIF, he can log in to the device by replaying the user's login packet.

NVD description · AI analysis pending
7.4
group max
<1%
  • dahuasecurity ipc-hdbw2431e-s-s2 firmware
  • dahuasecurity ipc-hdbw2831e-s-s2 firmware
  • dahuasecurity ipc-hdbw2230e-s-s2 firmware
  • +1 more
CVE-2021-33046
Some Dahua products have access control vulnerability in the password reset process.

Some Dahua products have access control vulnerability in the password reset process. Attackers can exploit this vulnerability through specific deployments to reset device passwords.

NVD description · AI analysis pending
9.81%
  • dahuasecurity ipc-hx1xxx firmware
  • dahuasecurity ipc-hx2xxx firmware
  • dahuasecurity ipc-hx3xxx firmware
  • +1 more
CVE-2021-33044
+1 in the same advisory: …33045
Authentication Bypass in Dahua IP Camera Firmware

Dahua IP cameras and related products contain an authentication bypass flaw (CWE-287, Improper Authentication) that is triggered when the client supplies the NetKeyboard type argument during the authentication process, allowing the device to treat the session as authenticated without valid credentials. An unauthenticated remote attacker who can reach the camera's network interface can exploit this to gain unauthorized access to the device's management functions. Successful exploitation can expose camera video streams and device configuration and can serve as a foothold into the surrounding surveillance or corporate network. Any organization running affected Dahua IP camera firmware, particularly cameras exposed to the internet, is potentially affected. The flaw is confirmed to be exploited in the wild: it was added to the CISA KEV on 2024-08-21, and EPSS assigns it a 99.9% probability of exploitation within 30 days (100th percentile), although no public PoC is known.

Do: Apply the mitigations or patched firmware specified in Dahua's security advisory for CVE-2021-33044; if mitigations are unavailable, discontinue use of the product as CISA's required action directs. Inventory internet-facing Dahua cameras and related devices, restrict their login interfaces from direct internet exposure, and review authentication logs for signs of prior exploitation. Ransomware use is listed as unknown, so treat any compromised camera as a potential network foothold and rotate any credentials used on the device.

9.8100% KEV PoC ×2
  • Dahua IP Camera Firmware
massplausibly millions of installed Dahua cameras worldwide, with likely >100,000 internet-exposed Dahua devices
CVE-2020-9502
+1 in the same advisory: …9682
Some Dahua products with Build time before December 2019 have Session ID predictable vulnerabilities.

Some Dahua products with Build time before December 2019 have Session ID predictable vulnerabilities. During normal user access, an attacker can use the predicted Session ID to construct a data packet to attack the device.

NVD description · AI analysis pending
9.8
group max
1%
  • dahuasecurity sd6al firmware
  • dahuasecurity sd5a firmware
  • dahuasecurity sd1a firmware
  • +1 more
CVE-2020-9501
Attackers can obtain Cloud Key information from the Dahua Web P2P control in specific ways.

Attackers can obtain Cloud Key information from the Dahua Web P2P control in specific ways. Cloud Key is used to authenticate the connection between the client tool and the platform. An attacker may use the leaked Cloud Key to impersonate the client to connect to the platform, resulting in additional consumption of platform server resources. Versions with Build time before April 2020 are affected.

NVD description · AI analysis pending
5.5<1%
  • dahuasecurity web p2p
CVE-2020-9499
+1 in the same advisory: …9500
Some Dahua products have buffer overflow vulnerabilities.

Some Dahua products have buffer overflow vulnerabilities. After the successful login of the legal account, the attacker sends a specific DDNS test command, which may cause the device to go down.

NVD description · AI analysis pending
7.2
group max
2%
  • dahuasecurity sd6al firmware
  • dahuasecurity sd5a firmware
  • dahuasecurity sd1a firmware
  • +1 more
CVE-2019-9677
+3 in the same advisory: …9679 …9678 …9680
The specific fields of CGI interface of some Dahua products are not strictly verified, an attacker can cause a buffer overflow by constructing malicious packets.

The specific fields of CGI interface of some Dahua products are not strictly verified, an attacker can cause a buffer overflow by constructing malicious packets. Affected products include: IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-HFW2X2X,IPC-HDW4X2X,IPC-HFW4X2X,IPC-HDBW4X2X,IPC-HDW5X2X,IPC-HFW5X2X for versions which Build time is before August 18, 2019.

NVD description · AI analysis pending
9.8
group max
1%
  • dahuasecurity ipc-hdw1x2x firmware
  • dahuasecurity ipc-hfw1x2x firmware
  • dahuasecurity ipc-hdw2x2x firmware
  • +1 more
CVE-2019-9681
Online upgrade information in some firmware packages of Dahua products is not encrypted.

Online upgrade information in some firmware packages of Dahua products is not encrypted. Attackers can obtain this information by analyzing firmware packages by specific means. Affected products include: IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-HFW2X2X,IPC-HDW4X2X,IPC-HFW4X2X,IPC-HDBW4X2X,IPC-HDW5X2X,IPC-HFW5X2X for versions which Build time is before August 18,2019.

NVD description · AI analysis pending
5.3<1%
  • dahuasecurity ipc-hdw1x2x firmware
  • dahuasecurity ipc-hfw1x2x firmware
  • dahuasecurity ipc-hdw2x2x firmware
  • +1 more
CVE-2019-9676
Buffer overflow vulnerability found in some Dahua IP Camera devices IPC-HFW1XXX,IPC-HDW1XXX,IPC-HFW2XXX Build before 2018/11.

Buffer overflow vulnerability found in some Dahua IP Camera devices IPC-HFW1XXX,IPC-HDW1XXX,IPC-HFW2XXX Build before 2018/11. The vulnerability exits in the function of redirection display for serial port printing information, which can not be used by product basic functions. After an attacker logs in locally, this vulnerability can be exploited to cause device restart or arbitrary code execution. Dahua has identified the corresponding security problems in the static code auditing process, so it has gradually deleted this function, which is no longer available in the newer devices and softwares. Dahua has released versions of the affected products to fix the vulnerability.

NVD description · AI analysis pending
7.8<1%
  • dahuasecurity ipc-hfw1xxx firmware
  • dahuasecurity ipc-hdw1xxx firmware
  • dahuasecurity ipc-hfw2xxx firmware
CVE-2017-3223
Dahua IP camera products using firmware versions prior to V2.400.0000.14.R.20170713 include a version of the Sonia web interface that may be vulnerable to a sta

Dahua IP camera products using firmware versions prior to V2.400.0000.14.R.20170713 include a version of the Sonia web interface that may be vulnerable to a stack buffer overflow. Dahua IP camera products include an application known as Sonia (/usr/bin/sonia) that provides the web interface and other services for controlling the IP camera remotely. Versions of Sonia included in firmware versions prior to DH_IPC-Consumer-Zi-Themis_Eng_P_V2.408.0000.11.R.20170621 do not validate input data length for the 'password' field of the web interface. A remote, unauthenticated attacker may submit a crafted POST request to the IP camera's Sonia web interface that may lead to out-of-bounds memory operations and loss of availability or remote code execution. The issue was originally identified by the researcher in firmware version DH_IPC-HX1X2X-Themis_EngSpnFrn_N_V2.400.0000.30.R.20160803.

NVD description · AI analysis pending
9.85%
  • dahuasecurity ip camera firmware
CVE-2017-9317
Privilege escalation vulnerability found in some Dahua IP devices.

Privilege escalation vulnerability found in some Dahua IP devices. Attacker in possession of low privilege account can gain access to credential information of high privilege account and further obtain device information or attack the device.

NVD description · AI analysis pending
8.8<1%
  • dahuasecurity xvr5x16 firmware
  • dahuasecurity xvr5x08 firmware
  • dahuasecurity xvr5x04 firmware
  • +1 more
CVE-2017-9315
Customer of Dahua IP camera or IP PTZ could submit relevant device information to receive a time limited temporary password from Dahua authorized dealer to rese

Customer of Dahua IP camera or IP PTZ could submit relevant device information to receive a time limited temporary password from Dahua authorized dealer to reset the admin password. The algorithm used in this mechanism is potentially at risk of being compromised and subsequently utilized by attacker.

NVD description · AI analysis pending
9.81%
  • dahuasecurity ipc-hfw1xxx firmware
  • dahuasecurity ipc-hdw1xxx firmware
  • dahuasecurity ipc-hdbw1xxx firmware
  • +1 more
CVE-2017-9316
Firmware upgrade authentication bypass vulnerability was found in Dahua IPC-HDW4300S and some IP products.

Firmware upgrade authentication bypass vulnerability was found in Dahua IPC-HDW4300S and some IP products. The vulnerability was caused by internal Debug function. This particular function was used for problem analysis and performance tuning during product development phase. It allowed the device to receive only specific data (one direction, no transmit) and therefore it was not involved in any instance of collecting user privacy data or allowing remote code execution.

NVD description · AI analysis pending
6.52%
  • dahuasecurity nvr11hs firmware
  • dahuasecurity ipc-hdw4300s firmware
  • dahuasecurity ipc-hfw4x00 firmware
  • +1 more
CVE-2017-9314
Authentication vulnerability found in Dahua NVR models NVR50XX, NVR52XX, NVR54XX, NVR58XX with software before DH_NVR5xxx_Eng_P_V2.616.0000.0.R.20171102.

Authentication vulnerability found in Dahua NVR models NVR50XX, NVR52XX, NVR54XX, NVR58XX with software before DH_NVR5xxx_Eng_P_V2.616.0000.0.R.20171102. Attacker could exploit this vulnerability to gain access to additional operations by means of forging json message.

NVD description · AI analysis pending
8.8<1%
  • dahuasecurity nvr5464-16p-4ks2 firmware
  • dahuasecurity nvr5208-8p-4ks2 firmware
  • dahuasecurity nvr5432-16p-4ks2 firmware
  • +1 more
CVE-2017-7925
+1 in the same advisory: …7927
A Password in Configuration File issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, DH-IPC-H

A Password in Configuration File issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, DH-IPC-HFW1XXX, DH-IPC-HFW2XXX, DH-IPC-HFW4XXX, DH-SD6CXX, DH-NVR1XXX, DH-HCVR4XXX, DH-HCVR5XXX, DHI-HCVR51A04HE-S3, DHI-HCVR51A08HE-S3, and DHI-HCVR58A32S-S2 devices. The password in configuration file vulnerability was identified, which could lead to a malicious user assuming the identity of a privileged user and gaining access to sensitive information.

NVD description · AI analysis pending
9.8
group max
51%
  • dahuasecurity dh-ipc-hdbw23a0rn-zs firmware
  • dahuasecurity dh-ipc-hdbw13a0sn firmware
  • dahuasecurity dh-ipc-hdw1xxx firmware
  • +1 more
CVE-2017-7253
Dahua IP Camera devices 3.200.0001.6 can be exploited via these steps:

Dahua IP Camera devices 3.200.0001.6 can be exploited via these steps: 1. Use the default low-privilege credentials to list all users via a request to a certain URI. 2. Login to the IP camera with admin credentials so as to obtain full control of the target IP camera. During exploitation, the first JSON object encountered has a "Component error: login challenge!" message. The second JSON object encountered has a result indicating a successful admin login.

NVD description · AI analysis pending
8.83% PoC
  • dahuasecurity ip camera firmware
CVE-2017-6432
An issue was discovered on Dahua DHI-HCVR7216A-S3 3.210.0001.10 build 2016-06-06 devices.

An issue was discovered on Dahua DHI-HCVR7216A-S3 3.210.0001.10 build 2016-06-06 devices. The Dahua DVR Protocol, which operates on TCP Port 37777, is an unencrypted, binary protocol. Performing a Man-in-the-Middle attack allows both sniffing and injections of packets, which allows creation of fully privileged new users, in addition to capture of sensitive information.

NVD description · AI analysis pending
8.1<1%
  • dahuasecurity nvr firmware
CVE-2017-6343
The web interface on Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2.400.0000.28.R 2016-03-29, and SmartPSS Softwar

The web interface on Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2.400.0000.28.R 2016-03-29, and SmartPSS Software 1.16.1 2017-01-19 allows remote attackers to obtain login access by leveraging knowledge of the MD5 Admin Hash without knowledge of the corresponding password, a different vulnerability than CVE-2013-6117.

NVD description · AI analysis pending
8.160%
  • dahuasecurity camera firmware
  • dahuasecurity nvr firmware
  • dahuasecurity smartpss firmware