VYPR

EIMS

by Dahua

CVEs (1)

  • CVE-2024-13985CriAug 27, 2025
    risk 0.66cvss epss 0.13

    A command injection vulnerability in Dahua EIMS versions prior to 2240008 allows unauthenticated remote attackers to execute arbitrary system commands via the capture_handle.action interface. The flaw stems from improper input validation in the captureCommand parameter, which is…