Medium severity6.8NVD Advisory· Published Oct 15, 2025· Updated Jun 17, 2026
CVE-2025-31702
CVE-2025-31702
Description
A vulnerability exists in certain Dahua embedded products. Third-party malicious attacker with obtained normal user credentials could exploit the vulnerability to access certain data which are restricted to admin privileges, such as system-sensitive files through specific HTTP request. This may cause tampering with admin password, leading to privilege escalation. Systems with only admin account are not affected.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
2- Dahua Camera Backdoor Survives Password Changes and Factory Resets on Compromised DevicesCyber Security News · Sep 4, 2026
- Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2PThe Hacker News · Aug 19, 2026