Unrated severityNVD Advisory· Published Mar 18, 2026· Updated Mar 18, 2026
CVE-2025-31703
CVE-2025-31703
Description
A vulnerability found in Dahua NVR/XVR device. A third-party malicious attacker with physical access to the device may gain access to a restricted shell via the serial port, and bypasses the shell's authentication mechanism to escalate privileges.
Affected products
3- dahua/NVR2-4KS3v5Range: Versions which Build time prior to 3rd March 2026
- dahua/XVR1B16H-I/Tv5Range: Versions which Build time prior to 3rd March 2026
- dahua/XVR4232AN-I/Tv5Range: Versions which Build time prior to 3rd March 2026
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.