VYPR
Unrated severityNVD Advisory· Published Mar 18, 2026· Updated Mar 18, 2026

CVE-2025-31703

CVE-2025-31703

Description

A vulnerability found in Dahua NVR/XVR device. A third-party malicious attacker with physical access to the device may gain access to a restricted shell via the serial port, and bypasses the shell's authentication mechanism to escalate privileges.

Affected products

3
  • dahua/NVR2-4KS3v5
    Range: Versions which Build time prior to 3rd March 2026
  • dahua/XVR1B16H-I/Tv5
    Range: Versions which Build time prior to 3rd March 2026
  • dahua/XVR4232AN-I/Tv5
    Range: Versions which Build time prior to 3rd March 2026

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.