VYPR

Dahua products

by Dahua

CVEs (22)

  • CVE-2021-33045CriKEVSep 15, 2021
    risk 0.84cvss 9.8epss 1.00

    The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.

  • CVE-2021-33044CriKEVSep 15, 2021
    risk 0.84cvss 9.8epss 1.00

    The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.

  • CVE-2021-33046CriJan 13, 2022
    risk 0.64cvss 9.8epss 0.01

    Some Dahua products have access control vulnerability in the password reset process. Attackers can exploit this vulnerability through specific deployments to reset device passwords.

  • CVE-2020-9502CriMay 13, 2020
    risk 0.64cvss 9.8epss 0.02

    Some Dahua products with Build time before December 2019 have Session ID predictable vulnerabilities. During normal user access, an attacker can use the predicted Session ID to construct a data packet to attack the device.

  • CVE-2026-29116HigJun 10, 2026
    risk 0.57cvss epss 0.00

    A vulnerability has been found in some Dahua products could allow an unauthenticated remote attacker to send a specially crafted packet, triggering an exception that causes the system to reboot unexpectedly, resulting in a denial of service.

  • CVE-2024-39950HigJul 31, 2024
    risk 0.56cvss 8.6epss 0.00

    A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities to initiate device initialization.

  • CVE-2025-31701HigJul 23, 2025
    risk 0.53cvss 8.1epss 0.01

    A vulnerability has been found in Dahua products. Attackers could exploit a buffer overflow vulnerability by sending specially crafted malicious packets, potentially causing service disruption (e.g., crashes) or remote code execution (RCE). Some devices may have deployed…

  • CVE-2025-31700HigJul 23, 2025
    risk 0.53cvss 8.1epss 0.01

    A vulnerability has been found in Dahua products. Attackers could exploit a buffer overflow vulnerability by sending specially crafted malicious packets, potentially causing service disruption (e.g., crashes) or remote code execution (RCE). Some devices may have deployed…

  • CVE-2024-39949HigJul 31, 2024
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities, causing the device to crash.

  • CVE-2024-39948HigJul 31, 2024
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities, causing the device to crash.

  • CVE-2024-39944HigJul 31, 2024
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been found in Dahua products.Attackers can send carefully crafted data packets to the interface with vulnerabilities, causing the device to crash.

  • CVE-2022-45429HigDec 27, 2022
    risk 0.49cvss 7.5epss 0.01

    Some Dahua software products have a vulnerability of server-side request forgery (SSRF). An Attacker can access internal resources by concatenating links (URL) that conform to specific rules.

  • CVE-2022-45425HigDec 27, 2022
    risk 0.49cvss 7.5epss 0.01

    Some Dahua software products have a vulnerability of using of hard-coded cryptographic key. An attacker can obtain the AES crypto key by exploiting this vulnerability.

  • CVE-2022-45423HigDec 27, 2022
    risk 0.49cvss 7.5epss 0.01

    Some Dahua software products have a vulnerability of unauthenticated request of MQTT credentials. An attacker can obtain encrypted MQTT credentials by sending a specific crafted packet to the vulnerable interface (the credentials cannot be directly exploited).

  • CVE-2020-9499HigApr 9, 2020
    risk 0.47cvss 7.2epss 0.01

    Some Dahua products have buffer overflow vulnerabilities. After the successful login of the legal account, the attacker sends a specific DDNS test command, which may cause the device to go down.

  • CVE-2024-39947MedJul 31, 2024
    risk 0.42cvss 6.5epss 0.00

    A vulnerability has been found in Dahua products.After obtaining the ordinary user's username and password, the attacker can send a carefully crafted data packet to the interface with vulnerabilities, causing the device to crash.

  • CVE-2022-45426MedDec 27, 2022
    risk 0.42cvss 6.5epss 0.01

    Some Dahua software products have a vulnerability of unrestricted download of file. After obtaining the permissions of ordinary users, by sending a specific crafted packet to the vulnerable interface, an attacker can download arbitrary files.

  • CVE-2024-39946MedJul 31, 2024
    risk 0.39cvss 6.0epss 0.00

    A vulnerability has been found in Dahua products.After obtaining the administrator's username and password, the attacker can send a carefully crafted data packet to the interface with vulnerabilities, causing device initialization.

  • CVE-2022-45424MedDec 27, 2022
    risk 0.35cvss 5.3epss 0.01

    Some Dahua software products have a vulnerability of unauthenticated request of AES crypto key. An attacker can obtain the AES crypto key by sending a specific crafted packet to the vulnerable interface.

  • CVE-2024-39945MedJul 31, 2024
    risk 0.32cvss 4.9epss 0.00

    A vulnerability has been found in Dahua products.  After obtaining the administrator's username and password, the attacker can send a carefully crafted data packet to the interface with vulnerabilities, causing the device to crash.

Page 1 of 2