logo

Dahua Camera flaws allow remote hacking. Update firmware now

ID: dde58455-8bba-5faa-aa7e-c98efb67b826

STIX ID: report--dde58455-8bba-5faa-aa7e-c98efb67b826

Feed Name: Security Affairs

Threat Score
80/100

Date Published: 2025-07-31

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Bitdefender reported two high-severity unauthenticated RCE vulnerabilities (CVE-2025-31700, CVE-2025-31701) in Dahua Hero C1 and several other Dahua camera models that allow attackers to achieve root access remotely via crafted HTTP headers and an undocumented RPC upload endpoint; researchers produced a PoC demonstrating ROP-based command execution, ELF payload delivery via TFTP, and a bind shell on port 4444. Dahua released firmware patches (coordinated disclosure completed July 23, 2025); users are urged to update firmware, disable UPnP/port forwarding, and isolate devices until patched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.