VYPR
Vendor

Dahuasecurity

Products
341
CVEs
58
Across products
243
Status
Private

Products

341
View all 341 products →

Recent CVEs

58
View all 58 CVEs →
  • CVE-2021-33045CriKEVSep 15, 2021
    risk 0.84cvss 9.8epss 1.00

    The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.

  • CVE-2021-33044CriKEVSep 15, 2021
    risk 0.84cvss 9.8epss 1.00

    The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.

  • CVE-2017-7925CriMay 6, 2017
    risk 0.68cvss 9.8epss 0.51

    A Password in Configuration File issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, DH-IPC-HFW1XXX, DH-IPC-HFW2XXX, DH-IPC-HFW4XXX, DH-SD6CXX, DH-NVR1XXX, DH-HCVR4XXX, DH-HCVR5XXX, DHI-HCVR51A04HE-S3,…

  • CVE-2017-6342CriFeb 27, 2017
    risk 0.65cvss 9.8epss 0.13

    An issue was discovered on Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2.400.0000.28.R 2016-03-29, and SmartPSS Software 1.16.1 2017-01-19. When SmartPSS Software is launched, while on the login screen, the software in the…

  • CVE-2021-33046CriJan 13, 2022
    risk 0.64cvss 9.8epss 0.01

    Some Dahua products have access control vulnerability in the password reset process. Attackers can exploit this vulnerability through specific deployments to reset device passwords.

  • CVE-2020-9502CriMay 13, 2020
    risk 0.64cvss 9.8epss 0.01

    Some Dahua products with Build time before December 2019 have Session ID predictable vulnerabilities. During normal user access, an attacker can use the predicted Session ID to construct a data packet to attack the device.

  • CVE-2019-9677CriSep 18, 2019
    risk 0.64cvss 9.8epss 0.01

    The specific fields of CGI interface of some Dahua products are not strictly verified, an attacker can cause a buffer overflow by constructing malicious packets. Affected products include: IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-HFW2X2X,IPC-HDW4X2X,IPC-HFW4X2X,IPC-HDBW4X2X,IPC-HD…

  • CVE-2017-3223CriJul 24, 2018
    risk 0.64cvss 9.8epss 0.05

    Dahua IP camera products using firmware versions prior to V2.400.0000.14.R.20170713 include a version of the Sonia web interface that may be vulnerable to a stack buffer overflow. Dahua IP camera products include an application known as Sonia (/usr/bin/sonia) that provides the…

  • CVE-2017-9315CriNov 28, 2017
    risk 0.64cvss 9.8epss 0.01

    Customer of Dahua IP camera or IP PTZ could submit relevant device information to receive a time limited temporary password from Dahua authorized dealer to reset the admin password. The algorithm used in this mechanism is potentially at risk of being compromised and subsequently…

  • CVE-2019-9679HigSep 18, 2019
    risk 0.57cvss 8.8epss 0.01

    Some of Dahua's Debug functions do not have permission separation. Low-privileged users can use the Debug function after logging in. Affected products include: IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-HFW2X2X,IPC-HDW4X2X,IPC-HFW4X2X,IPC-HDBW4X2X,IPC-HDW5X2X,IPC-HFW5X2X for…

  • CVE-2017-9317HigMay 23, 2018
    risk 0.57cvss 8.8epss 0.01

    Privilege escalation vulnerability found in some Dahua IP devices. Attacker in possession of low privilege account can gain access to credential information of high privilege account and further obtain device information or attack the device.

  • CVE-2017-9314HigNov 13, 2017
    risk 0.57cvss 8.8epss 0.01

    Authentication vulnerability found in Dahua NVR models NVR50XX, NVR52XX, NVR54XX, NVR58XX with software before DH_NVR5xxx_Eng_P_V2.616.0000.0.R.20171102. Attacker could exploit this vulnerability to gain access to additional operations by means of forging json message.

  • CVE-2017-7253HigMar 30, 2017
    risk 0.57cvss 8.8epss 0.03

    Dahua IP Camera devices 3.200.0001.6 can be exploited via these steps: 1. Use the default low-privilege credentials to list all users via a request to a certain URI. 2. Login to the IP camera with admin credentials so as to obtain full control of the target IP camera. During…

  • CVE-2017-6343HigFeb 27, 2017
    risk 0.57cvss 8.1epss 0.60

    The web interface on Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2.400.0000.28.R 2016-03-29, and SmartPSS Software 1.16.1 2017-01-19 allows remote attackers to obtain login access by leveraging knowledge of the MD5 Admin Hash…

  • CVE-2024-39950HigJul 31, 2024
    risk 0.56cvss 8.6epss 0.00

    A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities to initiate device initialization.

  • CVE-2019-9682HigMay 13, 2020
    risk 0.53cvss 8.1epss 0.01

    Dahua devices with Build time before December 2019 use strong security login mode by default, but in order to be compatible with the normal login of early devices, some devices retain the weak security login mode that users can control. If the user uses a weak security login…

  • CVE-2017-6432HigMar 9, 2017
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered on Dahua DHI-HCVR7216A-S3 3.210.0001.10 build 2016-06-06 devices. The Dahua DVR Protocol, which operates on TCP Port 37777, is an unencrypted, binary protocol. Performing a Man-in-the-Middle attack allows both sniffing and injections of packets, which…

  • CVE-2019-9676HigJun 12, 2019
    risk 0.51cvss 7.8epss 0.00

    Buffer overflow vulnerability found in some Dahua IP Camera devices IPC-HFW1XXX,IPC-HDW1XXX,IPC-HFW2XXX Build before 2018/11. The vulnerability exits in the function of redirection display for serial port printing information, which can not be used by product basic functions.…

  • CVE-2017-7927HigMay 6, 2017
    risk 0.50cvss 7.3epss 0.37

    A Use of Password Hash Instead of Password for Authentication issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, DH-IPC-HFW1XXX, DH-IPC-HFW2XXX, DH-IPC-HFW4XXX, DH-SD6CXX, DH-NVR1XXX, DH-HCVR4XXX, DH-HCVR5XXX,…

  • CVE-2024-39949HigJul 31, 2024
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities, causing the device to crash.