logo

Vulnerabilities Identified in Dahua Hero C1 Smart Cameras

ID: 07bda3a5-5448-523b-9cbd-fb97f5a9e113

STIX ID: report--07bda3a5-5448-523b-9cbd-fb97f5a9e113

Feed Name: Bitdefender Labs

Threat Score
78/100

Date Published: 2025-07-30

Date Updated: 2026-04-27

Author: Bitdefender

...
...

Bitdefender disclosed two critical unauthenticated RCE vulnerabilities (CVE-2025-31700 and CVE-2025-31701) in Dahua Hero C1 and related IPC models that permit root access and persistent, unsigned payloads via crafted ONVIF Host headers and RPC upload handlers; researcher PoCs demonstrate ELF payload delivery and bind shells, and Dahua published fixes in July 2025—users should patch affected firmware, avoid exposing cameras to the internet, disable UPnP, and isolate devices on a separate network.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.