Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2025-31702

Quick assessment

Affected
Dahua IPC
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Dahua IPC和Dahua SD都是中国大华(Dahua)公司的产品。Dahua IPC是大华的一系列工控机。Dahua SD是一系列云台球型摄像机。 Dahua IPC和Dahua SD存在安全漏洞,该漏洞源于第三方恶意攻击者可通过特定HTTP请求访问系统敏感文件等管理员权限数据,可能导致管理员密码篡改和权限提升。

CVSS 6.8 · Medium EPSS 0.46% · P38
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2025-31702

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
A vulnerability exists in certain Dahua embedded products. Third-party malicious attacker with obtained normal user credentials could exploit the vulnerability to access certain data which are restricted to admin privileges, such as system-sensitive files through specific HTTP request. This may cause tampering with admin password, leading to privilege escalation. Systems with only admin account are not affected.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
关键资源的不正确权限授予
Source: CVE Program / CVE List V5
Vulnerability Title
Dahua IPC和Dahua SD 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Dahua IPC和Dahua SD都是中国大华(Dahua)公司的产品。Dahua IPC是大华的一系列工控机。Dahua SD是一系列云台球型摄像机。 Dahua IPC和Dahua SD存在安全漏洞,该漏洞源于第三方恶意攻击者可通过特定HTTP请求访问系统敏感文件等管理员权限数据,可能导致管理员密码篡改和权限提升。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Dahua IPC Affected products include certain models from the IPC-1XXX, IPC-2XXX, IPC-WX, and IPC-ECXX series, and limited to versions which build time prior to 1st July 2025 (not including 1st July 2025). -
Dahua SD Affected products include certain models from the SD3A, SD2A, SD3D, SDT2A, and SD2C series, and limited to versions which build time prior to 1st July 2025 (not including 1st July 2025). -

II. Public POCs for CVE-2025-31702

# POC Description Source Link Shenlong Link
1 Repository with tools, exploits, and material associated with the analysis and discovery process of CVE-2025-31702 and other related security issues. https://github.com/purpleghosts/CVE-2025-31702 POC Details
2 Repository with tools, exploits, and material associated with the analysis and discovery process of CVE-2025-31702 and other related security issues. https://github.com/itres-labs/CVE-2025-31702 POC Details
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-31702

请登录查看更多情报信息。

Other References for CVE-2025-31702 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2025-31702

No comments yet


Leave a comment