Show filters
61 Total Results
Displaying 1-10 of 61
Sort by:
Attacker Value
Very High

CVE-2021-33045

Disclosure Date: September 15, 2021 (last updated February 23, 2025)
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.
Attacker Value
Unknown

CVE-2021-33044

Disclosure Date: September 15, 2021 (last updated February 23, 2025)
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.
Attacker Value
Unknown

CVE-2024-13131

Disclosure Date: January 05, 2025 (last updated January 14, 2025)
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-9680. Reason: This candidate is a reservation duplicate of CVE-2019-9680. Notes: All CVE users should reference CVE-2019-9680 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.
0
Attacker Value
Unknown

CVE-2024-13130

Disclosure Date: January 05, 2025 (last updated January 13, 2025)
A vulnerability was found in Dahua IPC-HFW1200S, IPC-HFW2300R-Z, IPC-HFW5220E-Z and IPC-HDW1200S up to 20241222. It has been rated as problematic. Affected by this issue is some unknown functionality of the file ../mtd/Config/Sha1Account1 of the component Web Interface. The manipulation leads to path traversal: '../filedir'. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown

CVE-2024-39950

Disclosure Date: July 31, 2024 (last updated August 20, 2024)
A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities to initiate device initialization.
Attacker Value
Unknown

CVE-2024-39949

Disclosure Date: July 31, 2024 (last updated August 20, 2024)
A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities, causing the device to crash.
Attacker Value
Unknown

CVE-2024-39948

Disclosure Date: July 31, 2024 (last updated August 20, 2024)
A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities, causing the device to crash.
Attacker Value
Unknown

CVE-2024-39947

Disclosure Date: July 31, 2024 (last updated August 20, 2024)
A vulnerability has been found in Dahua products.After obtaining the ordinary user's username and password, the attacker can send a carefully crafted data packet to the interface with vulnerabilities, causing the device to crash.
Attacker Value
Unknown

CVE-2024-39946

Disclosure Date: July 31, 2024 (last updated August 20, 2024)
A vulnerability has been found in Dahua products.After obtaining the administrator's username and password, the attacker can send a carefully crafted data packet to the interface with vulnerabilities, causing device initialization.
Attacker Value
Unknown

CVE-2024-39945

Disclosure Date: July 31, 2024 (last updated August 20, 2024)
A vulnerability has been found in Dahua products.  After obtaining the administrator's username and password, the attacker can send a carefully crafted data packet to the interface with vulnerabilities, causing the device to crash.