Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2025-31702 PoC — Dahua IPC和Dahua SD 安全漏洞

Source
Associated Vulnerability
Title: Dahua IPC和Dahua SD 安全漏洞 (CVE-2025-31702)
Description:A vulnerability exists in certain Dahua embedded products. Third-party malicious attacker with obtained normal user credentials could exploit the vulnerability to access certain data which are restricted to admin privileges, such as system-sensitive files through specific HTTP request. This may cause tampering with admin password, leading to privilege escalation. Systems with only admin account are not affected.
Description
Repository with tools, exploits, and material associated with the analysis and discovery process of CVE-2025-31702 and other related security issues.
Readme
# CVE-2025-31702 — Research tools & DFIR material

**Repository with tools, exploits and research artefacts related to the analysis and discovery of CVE-2025-31702 and related issues.**

---

## Overview

This project collects the material used in the investigation of **CVE-2025-31702** and related operational issues (notably P2P/Easy4IP exposure and auto-update inconsistencies). It includes lab scripts, parsers and notes that helped reproduce and validate behaviours seen during DFIR. The code is intended for *defensive* use in authorized environments only.

---

## Scope & goals

* Provide safe, auditable utilities for defenders to validate their deployments.
* Offer detection ideas and mitigation guidance SOC/IR teams can adopt.
* Keep research artifacts and PoCs documented for transparency.

---

## Legal notice & responsible use

**READ THIS BEFORE USING ANY TOOL**

This repository contains tools that interact with vendor infrastructure and devices. They are **intended only for use on devices you own or systems for which you have explicit written permission to test**.

* Unauthorized use is likely illegal and may cause service disruption.
* Before running tools against any network/device, get written authorization.

---

## Requirements & installation

Minimum environment:

* Python 3.10+

---
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →