Dahuasecurity
dahuasecurity
58 CVEs • 748 products
Products (748)
Click to collapseToggle
Products (748)
Click to collapse
CVEs (58)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Dahuasecurity 1Ip Camera Firmware Nov 21, 2024 Jul 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Dahua IP camera products using firmware versions prior to V2.400.0000.14.R.20170713 include a version of the Sonia web interface that may be vulnerable to a stack buffer overflow. Dahua IP camera products include an appl...Show more |
1Dahuasecurity 6Ipc Hdbw4xxx Firmware Ipc Hdbw5xxx FirmwareXvr5x04 Firmware+3 moreNov 21, 2024 May 23, 2018 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 Privilege escalation vulnerability found in some Dahua IP devices. Attacker in possession of low privilege account can gain access to credential information of high privilege account and further obtain device information...Show more |
1Dahuasecurity 25Dh Sd2xxxxx Firmware Dh Sd4xxxxx FirmwareDh Sd5xxxxx Firmware+22 moreMay 13, 2026 Nov 28, 2017 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Customer of Dahua IP camera or IP PTZ could submit relevant device information to receive a time limited temporary password from Dahua authorized dealer to reset the admin password. The algorithm used in this mechanism i...Show more |
1Dahuasecurity 9Ipc Hdbw4x00 Firmware Ipc Hdbw5x00 FirmwareIpc Hdw4300s Firmware+6 moreMay 13, 2026 Nov 27, 2017 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 Firmware upgrade authentication bypass vulnerability was found in Dahua IPC-HDW4300S and some IP products. The vulnerability was caused by internal Debug function. This particular function was used for problem analysis a...Show more |
1Dahuasecurity 22Nvr5208 4ks2 Firmware Nvr5208 8p 4ks2 FirmwareNvr5216 16p 4ks2 Firmware+19 moreMay 13, 2026 Nov 13, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Authentication vulnerability found in Dahua NVR models NVR50XX, NVR52XX, NVR54XX, NVR58XX with software before DH_NVR5xxx_Eng_P_V2.616.0000.0.R.20171102. Attacker could exploit this vulnerability to gain access to additi...Show more |
1Dahuasecurity 15Dh Hcvr4xxx Firmware Dh Hcvr5xxx FirmwareDh Ipc Hdbw13a0sn Firmware+12 moreMay 13, 2026 May 6, 2017 N/A· v4 7.3 HIGH· v3 7.5 HIGH· v2 A Use of Password Hash Instead of Password for Authentication issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, DH-IPC-HFW1XXX, DH-IPC-HFW2XXX, DH-IPC-...Show more |
1Dahuasecurity 15Dh Hcvr4xxx Firmware Dh Hcvr5xxx FirmwareDh Ipc Hdbw13a0sn Firmware+12 moreMay 13, 2026 May 6, 2017 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 A Password in Configuration File issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, DH-IPC-HFW1XXX, DH-IPC-HFW2XXX, DH-IPC-HFW4XXX, DH-SD6CXX, DH-NVR1XX...Show more |
1Dahuasecurity 1Ip Camera Firmware May 13, 2026 Mar 30, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Dahua IP Camera devices 3.200.0001.6 can be exploited via these steps: 1. Use the default low-privilege credentials to list all users via a request to a certain URI. 2. Login to the IP camera with admin credentials so as...Show more |
An issue was discovered on Dahua DHI-HCVR7216A-S3 3.210.0001.10 build 2016-06-06 devices. The Dahua DVR Protocol, which operates on TCP Port 37777, is an unencrypted, binary protocol. Performing a Man-in-the-Middle attac...Show more |
1Dahuasecurity 3Camera Firmware Nvr FirmwareSmartpss FirmwareMay 13, 2026 Feb 27, 2017 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 The web interface on Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2.400.0000.28.R 2016-03-29, and SmartPSS Software 1.16.1 2017-01-19 allows remote attackers to obtain login...Show more |
1Dahuasecurity 3Camera Firmware Nvr FirmwareSmartpss FirmwareMay 13, 2026 Feb 27, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered on Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2.400.0000.28.R 2016-03-29, and SmartPSS Software 1.16.1 2017-01-19. When SmartPSS Software is launche...Show more |
1Dahuasecurity 3Camera Firmware Nvr FirmwareSmartpss FirmwareMay 13, 2026 Feb 27, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2.400.0000.28.R 2016-03-29, and SmartPSS Software 1.16.1 2017-01-19 send cleartext passwords in response to requests from the Web...Show more |
Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive information including user credentials, change user passwords, clear log files, and perform other actions via...Show more |
1Dahuasecurity 65Dvr0404hd A Dvr0404hd LDvr0404hd S+62 moreApr 29, 2026 Sep 17, 2013 N/A· v4 N/A· v3 10.0 HIGH· v2 The authorization implementation on Dahua DVR appliances accepts a hash string representing the current date for the role of a master password, which makes it easier for remote attackers to obtain administrative access a...Show more |
1Dahuasecurity 65Dvr0404hd A Dvr0404hd LDvr0404hd S+62 moreApr 29, 2026 Sep 17, 2013 N/A· v4 N/A· v3 7.8 HIGH· v2 Dahua DVR appliances use a password-hash algorithm with a short hash length, which makes it easier for context-dependent attackers to discover cleartext passwords via a brute-force attack. |
1Dahuasecurity 65Dvr0404hd A Dvr0404hd LDvr0404hd S+62 moreApr 29, 2026 Sep 17, 2013 N/A· v4 N/A· v3 9.3 HIGH· v2 Dahua DVR appliances have a small value for the maximum password length, which makes it easier for remote attackers to obtain access via a brute-force attack. |
1Dahuasecurity 65Dvr0404hd A Dvr0404hd LDvr0404hd S+62 moreApr 29, 2026 Sep 17, 2013 N/A· v4 N/A· v3 7.8 HIGH· v2 Dahua DVR appliances do not properly restrict UPnP requests, which makes it easier for remote attackers to obtain access via vectors involving a replay attack against the TELNET port. |
1Dahuasecurity 65Dvr0404hd A Dvr0404hd LDvr0404hd S+62 moreApr 29, 2026 Sep 17, 2013 N/A· v4 N/A· v3 10.0 HIGH· v2 Dahua DVR appliances have a hardcoded password for (1) the root account and (2) an unspecified "backdoor" account, which makes it easier for remote attackers to obtain administrative access via authorization requests inv...Show more |